Palo Alto Networks PAN-OS GlobalProtect Denial-of-Service Vulnerability

Vulnerability

A denial-of-service vulnerability has been identified in the GlobalProtect feature of Palo Alto Networks PAN-OS software. This vulnerability allows an unauthenticated attacker to disrupt service by sending a large volume of specially crafted packets over time. The issue impacts both the GlobalProtect portal and gateway, but does not affect Cloud NGFWs or Prisma Access software.

Impact

Exploitation of this vulnerability leads to a denial-of-service condition, causing the GlobalProtect service to become unavailable.

Remediation

Users can upgrade to PAN-OS 11.0.2 or later, PAN-OS 10.2.5 or later, or PAN-OS 10.1.14-h11 or later. For all other older unsupported PAN-OS versions, upgrade to a supported fixed version.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
5.7
impact
2.5
exploitability
7.0
remediation
7.7
relevance
0.0
threat
0.0
urgency
5.7
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.