- Description
- An insufficient certificate validation issue in the Palo Alto Networks GlobalProtect™ app enables attackers to connect the GlobalProtect app to arbitrary servers. This can enable a local non-administrative operating system user or an attacker on the same subnet to install malicious root certificates on the endpoint and subsequently install malicious software signed by the malicious root certificates on that endpoint.
- Source
- psirt@paloaltonetworks.com
- NVD status
- Deferred
CVSS 4.0
- Type
- Secondary
- Base score
- 5.3
- Impact score
- -
- Exploitability score
- -
- Vector string
- CVSS:4.0/AV:P/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:D/RE:X/U:Amber
- Severity
- MEDIUM
- psirt@paloaltonetworks.com
- CWE-295
- Hype score
- Not currently trending
CVE-2025-2183 is a critical certificate validation flaw in #PaloAlto #GlobalProtect VPN clients that allows attackers to redirect VPN connections and install malicious root certificates, bypassing protections and enabling persistent system compromise. https://t.co/uk0vWJRODX ht
@provintell
19 Aug 2025
12 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
یکی از قویترین سیستم های تشخیص حملات سایبری در دنیا Paolo alto می باشد . به تازگی برای یکی از برنامه های این محصول با نام GlobalProtect آسیب پذیری با کد شناسایی CVE-2025-2183
@AmirHossein_sec
17 Aug 2025
45 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
Palo Alto Networks の VPN クライアント「GlobalProtect」に、証明書検証の不備により権限昇格とマルウェアインストールを許す脆弱性(CVE-2025-2183)が発見された。 2025年8月13日に公開され、Windows・Linux版が対象で、And
@yousukezan
15 Aug 2025
1052 Impressions
6 Retweets
9 Likes
2 Bookmarks
0 Replies
0 Quotes
Michelin CERT striked back. A regression in #PaloAlto Global Protect (CVE-2025-2183) allowed to fully compromise remotely the workstation. All details will be revealed during my talk at @hack_lu. https://t.co/aCW0UOONsN
@Fisjkars
14 Aug 2025
20 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2025-2183 An insufficient certificate validation issue in the Palo Alto Networks GlobalProtect™ app enables attackers to connect the GlobalProtect app to arbitrary servers. This … https://t.co/cLwzo1BrVi
@CVEnew
13 Aug 2025
262 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes