CVE-2025-0126
PAN-OS: Session Fixation Vulnerability in GlobalProtect SAML Login
Description
When configured using SAML, a session fixation vulnerability in the GlobalProtect™ login enables an attacker to impersonate a legitimate authorized user and perform actions as that GlobalProtect user. This requires the legitimate user to first click on a malicious link provided by the attacker. The SAML login for the PAN-OS® management interface is not affected. Additionally, this issue does not affect Cloud NGFW and all Prisma® Access instances are proactively patched.
Weakness: CWE-384
Affected products
| Vendor | Product | Category | Matched by |
|---|---|---|---|
| Palo Alto Networks | Cloud NGFW | Firewall / NGFW | cna-assigner |
| Palo Alto Networks | PAN-OS | Firewall / NGFW | cna-assigner |
| Palo Alto Networks | Prisma Access | SASE / SSE / Secure Web | cna-assigner |
Vendor-reported affected versions (3)
- Palo Alto Networks · Cloud NGFW
- Palo Alto Networks · PAN-OS
- Palo Alto Networks · Prisma Access
Credit
D'Angelo Gonzalez of CrowdStrike
Vendor remediation
Version Minor Version Suggested Solution PAN-OS 11.2 11.2.0 through 11.2.2 Upgrade to 11.2.3 or laterPAN-OS 11.1 11.1.0 through 11.1.4 Upgrade to 11.1.5 or later PAN-OS 11.011.0.0 through 11.0.5Upgrade to 11.0.6 or laterPAN-OS 10.2 10.2.10 Upgrade to 10.2.10-h6 or 10.2.11 or later 10.2.5 through 10.2.9Upgrade to 10.2.9-h13 or 10.2.11 or later 10.2.0 through 10.2.4Upgrade to 10.2.4-h25 or 10.2.11 or laterPAN-OS 10.1 10.1.0 through 10.1.14 Upgrade to 10.1.14-h11 or later All other older unsupported PAN-OS versions Upgrade to a supported fixed version. PAN-OS 11.0 is EoL. We listed it in this section for completeness because we added a patch for PAN-OS 11.0 before it reached EoL. If you are running PAN-OS 11.0 in any of your firewalls, we strongly recommend that you upgrade from this EoL vulnerable version to a fixed version. We proactively initiated an upgrade of Prisma Access on March 21, 2025, to cover all tenants.