7.5
CVE-2025-0114
- EPSS 0.4%
- Veröffentlicht 12.03.2025 18:20:05
- Zuletzt bearbeitet 22.10.2025 19:23:43
- Erkennungen
PAN-OS: Denial of Service (DoS) in GlobalProtect
A Denial of Service (DoS) vulnerability in the GlobalProtect feature of Palo Alto Networks PAN-OS software enables an unauthenticated attacker to render the service unavailable by sending a large number of specially crafted packets over a period of time. This issue affects both the GlobalProtect portal and the GlobalProtect gateway. This issue does not apply to Cloud NGFWs or Prisma Access software.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Paloaltonetworks ≫ Pan-os Version >= 10.1.0 < 10.1.14
Paloaltonetworks ≫ Pan-os Version >= 10.2.0 < 10.2.5
Paloaltonetworks ≫ Pan-os Version >= 11.0.0 < 11.0.2
Paloaltonetworks ≫ Pan-os Version 10.1.14 Update h1
Paloaltonetworks ≫ Pan-os Version 10.1.14 Update h10
Paloaltonetworks ≫ Pan-os Version 10.1.14 Update h2
Paloaltonetworks ≫ Pan-os Version 10.1.14 Update h3
Paloaltonetworks ≫ Pan-os Version 10.1.14 Update h4
Paloaltonetworks ≫ Pan-os Version 10.1.14 Update h5
Paloaltonetworks ≫ Pan-os Version 10.1.14 Update h6
Paloaltonetworks ≫ Pan-os Version 10.1.14 Update h7
Paloaltonetworks ≫ Pan-os Version 10.1.14 Update h8
Paloaltonetworks ≫ Pan-os Version 10.1.14 Update h9
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.4% | 0.327 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
|
| psirt@paloaltonetworks.com | 8.2 | 0 | 0 |
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:C/RE:X/U:Amber
|
CWE-400 Uncontrolled Resource Consumption
The product does not properly control the allocation and maintenance of a limited resource.
https://security.paloaltonetworks.com/CVE-2025-0114