7.5

CVE-2025-0114

PAN-OS: Denial of Service (DoS) in GlobalProtect

A Denial of Service (DoS) vulnerability in the GlobalProtect feature of Palo Alto Networks PAN-OS software enables an unauthenticated attacker to render the service unavailable by sending a large number of specially crafted packets over a period of time. This issue affects both the GlobalProtect portal and the GlobalProtect gateway.

This issue does not apply to Cloud NGFWs or Prisma Access software.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Paloaltonetworks ≫ Pan-os Version >= 10.1.0 < 10.1.14
Paloaltonetworks ≫ Pan-os Version >= 10.2.0 < 10.2.5
Paloaltonetworks ≫ Pan-os Version >= 11.0.0 < 11.0.2
Paloaltonetworks ≫ Pan-os Version 10.1.14 Update h1
Paloaltonetworks ≫ Pan-os Version 10.1.14 Update h10
Paloaltonetworks ≫ Pan-os Version 10.1.14 Update h2
Paloaltonetworks ≫ Pan-os Version 10.1.14 Update h3
Paloaltonetworks ≫ Pan-os Version 10.1.14 Update h4
Paloaltonetworks ≫ Pan-os Version 10.1.14 Update h5
Paloaltonetworks ≫ Pan-os Version 10.1.14 Update h6
Paloaltonetworks ≫ Pan-os Version 10.1.14 Update h7
Paloaltonetworks ≫ Pan-os Version 10.1.14 Update h8
Paloaltonetworks ≫ Pan-os Version 10.1.14 Update h9
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.4% 0.327
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
psirt@paloaltonetworks.com 8.2 0 0
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:C/RE:X/U:Amber
CWE-400 Uncontrolled Resource Consumption

The product does not properly control the allocation and maintenance of a limited resource.

https://security.paloaltonetworks.com/CVE-2025-0114
Vendor Advisory