Impact
A buffer overflow in the GlobalProtect App during the UDP tunnel handshake allows a MitM or rogue gateway to disrupt system processes and possibly execute arbitrary code with SYSTEM/root privileges. The flaw is a classic out‑of‑bounds write (CWE‑787).
Affected Systems
Affected customers run Palo Alto Networks GlobalProtect App versions 6.0, 6.2, and 6.3 on Linux, macOS, Windows, iOS, Android, and ChromeOS. The CVE table lists vulnerable ranges: 6.0.0 through 6.0.14, 6.2.0 through 6.2.8, and 6.3.0 through 6.3.3‑h13 for Linux; analogous ranges for the other platforms as specified.
Risk and Exploitability
The CVSS score is 5.2 moderate risk; EPSS is not available, so current exploitation probability is unknown. The vulnerability is not listed in the CISA KEV catalog, suggesting no confirmed public exploits yet. The likely attack vector is remote via a UDP tunnel configured by an attacker‑controlled gateway or compromised portal, which is inferred from the description that a MitM can exploit the handshake.
OpenCVE Enrichment