Impact
Improper certificate validation in the Palo Alto Networks GlobalProtect app allows an unauthenticated attacker with man‑in‑the‑middle access to intercept and alter data transmitted by the application. The flaw is a misconfiguration that accepts any presented certificate, thereby bypassing the intended trust chain. This impacts data confidentiality and integrity at the application level, while the underlying VPN tunnel remains unaffected.
Affected Systems
The vulnerability affects the GlobalProtect App on Linux, macOS, and Windows running versions 6.0.0 through 6.0.14, 6.2.0 through 6.2.8‑h12, and 6.3.0 through 6.3.3‑h13. Users should upgrade to 6.0.15 or later, 6.2.8‑h13 or later, or 6.3.3‑h15 or later respectively. Versions for iOS, Android, and Chrome OS are not affected.
Risk and Exploitability
The CVSS score of 4.5 indicates moderate severity. The vulnerability is not listed in the CISA KEV catalog, and no EPSS value is reported. Based on the description, it is inferred that only attackers able to perform a Man‑in‑the‑Middle—such as those with access to unsecured or compromised networks—can exploit this weakness. The risk remains until the application is updated to a version that enforces strict certificate validation.
OpenCVE Enrichment