8.2
CVE-2025-0114
- EPSS 0.05%
- Published 12.03.2025 18:20:05
- Last modified 12.03.2025 19:15:37
- Source psirt@paloaltonetworks.com
- Teams watchlist Login
- Open Login
A Denial of Service (DoS) vulnerability in the GlobalProtect feature of Palo Alto Networks PAN-OS software enables an unauthenticated attacker to render the service unavailable by sending a large number of specially crafted packets over a period of time. This issue affects both the GlobalProtect portal and the GlobalProtect gateway. This issue does not apply to Cloud NGFWs or Prisma Access software.
Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
This information is available to logged-in users. Login
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
VendorPalo Alto Networks
≫
Product
PAN-OS
Default Statusunaffected
Version
11.2.0
Status
unaffected
Version
11.1.0
Status
unaffected
Version <
11.0.2
Version
11.0.0
Status
affected
Version <
10.2.5
Version
10.2.0
Status
affected
Version <
10.1.14-h11
Version
10.1.0
Status
affected
VendorPalo Alto Networks
≫
Product
Cloud NGFW
Default Statusunaffected
Version
All
Status
unaffected
VendorPalo Alto Networks
≫
Product
Prisma Access
Default Statusunaffected
Version
All
Status
unaffected
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.05% | 0.161 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
psirt@paloaltonetworks.com | 8.2 | 0 | 0 |
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:C/RE:X/U:Amber
|
CWE-400 Uncontrolled Resource Consumption
The product does not properly control the allocation and maintenance of a limited resource, thereby enabling an actor to influence the amount of resources consumed, eventually leading to the exhaustion of available resources.