Impact
An improper certificate validation flaw in the Prisma Access Agent for iOS allows an attacker to perform a man‑in‑the‑middle attack that intercepts VPN traffic. Because the client accepts certificates that should not be trusted, confidentiality of the data transmitted over the VPN can be compromised. This is a CWE‑295 weakness involving improper certificate validation. The CVSS score is 5.7, indicating a moderate level of severity. The EPSS score is <1%, and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector requires an attacker to either local network access or the ability to masquerade as a certificate authority. While the exploit is feasible, the low EPSS score and moderate CVSS indicate that the attack risk is not extreme, but the impact to confidentiality remains significant.
Affected Systems
The vulnerability affects only the iOS version of the Prisma Access Agent from Palo Alto Networks. Specifically, any installation of version 25.0 through 26.2 on iOS devices is impacted. Other operating systems—Windows, macOS, Linux, Android, and ChromeOS—are not affected.
Risk and Exploitability
The CVSS score of 5.7 reflects moderate severity, largely due to the impact on confidentiality and limited privilege escalation. The EPSS score of <1% indicates a low probability of current exploitation. The vulnerability is not included in CISA’s KEV catalog, suggesting no known widespread attacks. Attacking this flaw requires an iOS device running an affected Prisma Access Agent version (25.0 through 26.2) and the capability to supply a forged certificate, typically achievable via a compromised network environment or malicious certificate authority.
OpenCVE Enrichment