CVE-2025-0114
HIGH EPSS 30.0%
Published Mar 12, 20251y ago · Modified Jun 17, 20261w ago
8.2 CVSS 4.0
Published Mar 12, 2025 1y ago
Last Modified Jun 17, 2026 1w ago
Description
A Denial of Service (DoS) vulnerability in the GlobalProtect feature of Palo Alto Networks PAN-OS software enables an unauthenticated attacker to render the service unavailable by sending a large number of specially crafted packets over a period of time. This issue affects both the GlobalProtect portal and the GlobalProtect gateway. This issue does not apply to Cloud NGFWs or Prisma Access software.
CVSS Details
Base Score
Exploitability
Impact
Vector string
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:C/RE:X/U:Amber Attack Vector Network
Attack Complexity High
Privileges Required None
User Interaction None
Scope X
Threat Intelligence
EPSS Exploit Probability
30.0% percentile
Exploit & Patch Status
No Known Exploit
No Patch Available
Weaknesses 1
CWE-400 Uncontrolled Resource Consumption Resource Mgmt
Affected Products 13
| Vendor | Product | Version | Range |
|---|---|---|---|
| paloaltonetworks | pan-os | * | ≥10.1.0 – <10.1.14 |
| paloaltonetworks | pan-os | * | ≥10.2.0 – <10.2.5 |
| paloaltonetworks | pan-os | * | ≥11.0.0 – <11.0.2 |
| paloaltonetworks | pan-os | 10.1.14 | any |
| paloaltonetworks | pan-os | 10.1.14 | any |
| paloaltonetworks | pan-os | 10.1.14 | any |
| paloaltonetworks | pan-os | 10.1.14 | any |
| paloaltonetworks | pan-os | 10.1.14 | any |
| paloaltonetworks | pan-os | 10.1.14 | any |
| paloaltonetworks | pan-os | 10.1.14 | any |
| paloaltonetworks | pan-os | 10.1.14 | any |
| paloaltonetworks | pan-os | 10.1.14 | any |
| paloaltonetworks | pan-os | 10.1.14 | any |
References 1
- security.paloaltonetworks.com https://security.paloaltonetworks.com/CVE-2025-0114
Remediation
No remediation data recorded yet
Check vendor advisories and the NVD entry for patch availability.