CVE-2025-0126

PAN-OS: Session Fixation Vulnerability in GlobalProtect SAML Login

Severity
High 8.3
CVSS 4.0
Exploited
Not listed
EPSS
0.004
30.8th percentile
Discovered by
Third party
Published by the vendor
Published
Apr 11, 2025
Assigned by palo_alto

Description

When configured using SAML, a session fixation vulnerability in the GlobalProtect™ login enables an attacker to impersonate a legitimate authorized user and perform actions as that GlobalProtect user. This requires the legitimate user to first click on a malicious link provided by the attacker. The SAML login for the PAN-OS® management interface is not affected. Additionally, this issue does not affect Cloud NGFW and all Prisma® Access instances are proactively patched.

Weakness: CWE-384

Affected products

Vendor Product Category Matched by
Palo Alto Networks Cloud NGFW Firewall / NGFW cna-assigner
Palo Alto Networks PAN-OS Firewall / NGFW cna-assigner
Palo Alto Networks Prisma Access SASE / SSE / Secure Web cna-assigner
Vendor-reported affected versions (3)
  • Palo Alto Networks · Cloud NGFW
  • Palo Alto Networks · PAN-OS
  • Palo Alto Networks · Prisma Access

Credit

D'Angelo Gonzalez of CrowdStrike

Vendor remediation

Version Minor Version Suggested Solution PAN-OS 11.2 11.2.0 through 11.2.2 Upgrade to 11.2.3 or laterPAN-OS 11.1 11.1.0 through 11.1.4 Upgrade to 11.1.5 or later PAN-OS 11.011.0.0 through 11.0.5Upgrade to 11.0.6 or laterPAN-OS 10.2 10.2.10 Upgrade to 10.2.10-h6 or 10.2.11 or later  10.2.5 through 10.2.9Upgrade to 10.2.9-h13 or 10.2.11 or later 10.2.0 through 10.2.4Upgrade to 10.2.4-h25 or 10.2.11 or laterPAN-OS 10.1 10.1.0 through 10.1.14 Upgrade to 10.1.14-h11 or later All other older unsupported PAN-OS versions Upgrade to a supported fixed version. PAN-OS 11.0 is EoL. We listed it in this section for completeness because we added a patch for PAN-OS 11.0 before it reached EoL. If you are running PAN-OS 11.0 in any of your firewalls, we strongly recommend that you upgrade from this EoL vulnerable version to a fixed version. We proactively initiated an upgrade of Prisma Access on March 21, 2025, to cover all tenants.