PT-2025-16006 · Palo Alto Networks · Globalprotect

Dangelo Gonzalez

·

Published

2025-04-09

·

Updated

2025-04-23

·

CVE-2025-0126

CVSS v2.0

8.5

High

VectorAV:N/AC:L/Au:N/C:N/I:P/A:C
Name of the Vulnerable Software and Affected Versions: GlobalProtect versions (affected versions not specified)
Description: A session fixation issue in the GlobalProtect login, when configured using SAML, allows an attacker to impersonate a legitimate authorized user. This requires the legitimate user to first click on a malicious link provided by the attacker. The SAML login for the PAN-OS management interface is not affected. Additionally, this issue does not affect Cloud NGFW and all Prisma Access instances.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Session Fixation

Weakness Enumeration

Related Identifiers

BDU:2025-04902
CVE-2025-0126

Affected Products

Globalprotect