Impact
An authentication bypass in the Large Scale VPN (LSVPN) feature of Palo Alto Networks PAN‑OS can be exploited by an attacker with network access to forge authentication messages. The flaw does not provide arbitrary code execution but allows the attacker to set up an unauthorized site‑to‑site VPN tunnel, creating a covert channel between previously isolated networks for potential data exfiltration or lateral movement.
Affected Systems
PAN‑OS releases from 10.2.0 through 10.2.18‑h*, 11.1.0 through 11.1.15, 11.2.0 through 11.2.12, and 12.1.0 through 12.1.7‑h* are affected. Panorama, Cloud NGFW, and Prisma Access are not impacted by this vulnerability.
Risk and Exploitability
The CVSS v3 base score of 4.5 indicates moderate severity, and the EPSS score of less than 1 % suggests a low likelihood of exploitation in the wild. The flaw requires only network‑level access, no privileged local access or code execution, and it is not listed in the CISA KEV catalog.
OpenCVE Enrichment