Palo Alto Networks GlobalProtect是美国Palo Alto Networks公司的一套网络防护软件。该软件可提供防火墙监控及威胁预防等功能。 Palo Alto Networks GlobalProtect存在安全漏洞,该漏洞源于权限分配不当可能导致应用禁用。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Palo Alto Networks | GlobalProtect App | 6.3.0 ~ 6.3.3 |
cpe:2.3:a:paloaltonetworks:globalprotect_app:6.3.2:-:*:*:*:*:*:*
|
|
| Palo Alto Networks | GlobalProtect App | - |
cpe:2.3:a:paloaltonetworks:globalprotect_app:6.3.2:-:*:*:*:*:*:*
|
|
| Palo Alto Networks | GlobalProtect UWP App | - | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2025-0130 | PAN-OS: Firewall Denial-of-Service (DoS) in the Web-Proxy Feature via a Burst of Malicious | |
| CVE-2025-0132 | Cortex XDR Broker VM: Unauthenticated User Can Disable Internal Services | |
| CVE-2025-0133 | PAN-OS: Reflected Cross-Site Scripting (XSS) Vulnerability in GlobalProtect Gateway and Po | |
| CVE-2025-0134 | Cortex XDR Broker VM: Authenticated Code Injection Vulnerability in Broker VM | |
| CVE-2025-0137 | PAN-OS: Improper Neutralization of Input in the Management Web Interface | |
| CVE-2025-0138 | Prisma Cloud Compute Edition: Insufficient Session Expiration Vulnerability in the Web Int | |
| CVE-2025-0136 | PAN-OS: Unencrypted Data Transfer when using AES-128-CCM on Intel-based hardware devices |
No comments yet