5.2

CVE-2026-0297

GlobalProtect App: Buffer Overflow Vulnerability during UDP Tunnel Handshake

A buffer overflow vulnerability exists in the Palo Alto Networks GlobalProtect™ app that enables a man-in-the-middle (MitM) attacker or a rogue gateway to disrupt system processes and potentially execute arbitrary code with elevated privileges (SYSTEM privileges on Windows, and root privileges on macOS and Linux).
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerPalo Alto Networks
Produkt GlobalProtect App
Default Statusunaffected
Version 6.3.0
Version < 6.3.3-h15
Status affected
Version 6.2.0
Status affected
Version 6.0.0
Version < 6.0.15
Status affected
HerstellerPalo Alto Networks
Produkt GlobalProtect App
Default Statusunaffected
Version 6.3.0
Version < 6.3.3-h14
Status affected
Version 6.2.0
Version < 6.2.8-h13
Status affected
Version 6.0.0
Version < 6.0.15
Status affected
HerstellerPalo Alto Networks
Produkt GlobalProtect App
Default Statusunaffected
Version 6.3.0
Version < 6.3.5
Status affected
Version 6.0.0
Version < 6.0.15
Status affected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.16% 0.06
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
psirt@paloaltonetworks.com 5.2 0 0
CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:D/RE:M/U:Amber
CWE-787 Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.