Impact
Authentication bypass vulnerabilities in Palo Alto Networks GlobalProtect portal and gateway allow an attacker to bypass authentication requirements and establish an unauthorized VPN connection. The flaw removes the authentication barrier to the VPN, enabling the attacker to obtain a VPN session without proper credentials. The weakness corresponds to CWE-565, indicating a session management flaw.
Affected Systems
Affected systems include Palo Alto Networks PAN‑OS firmware. Vulnerable releases span 10.2.0 through 10.2.18‑h*, 11.1.0 through 11.1.15‑h*, 11.2.0 through 11.2.12, and 12.1.2 through 12.1.7 (including the patch‑level intervals listed in the vendor advisory). Palo Alto Networks Prisma Access versions 10.2.0 through 10.2.10‑h* and 11.2.0 through 11.2.7‑h* are likewise impacted. Panorama appliances and Cloud NGFW firmware are not affected.
Risk and Exploitability
The CVSS score of 7.8 indicates high severity. The EPSS score of 95% demonstrates a very high probability of exploitation. It is listed in the CISA KEV catalog, meaning it is actively exploited. The likely attack vector is remote, as the flaw allows an attacker to establish a VPN session without authenticating from any client that can reach the GlobalProtect portal or gateway.
OpenCVE Enrichment