CVE-2025-0133: PAN-OS: Reflected Cross-Site Scripting (XSS) Vulnerability in GlobalProtect Gateway and Portal

Published May 14, 2025
·
Updated

A reflected cross-site scripting (XSS) vulnerability in the GlobalProtect™ gateway and portal features of Palo Alto Networks PAN-OS® software enables execution of malicious JavaScript in the context of an authenticated Captive Portal user's browser when they click on a specially crafted link. The primary risk is phishing attacks that can lead to credential theft—particularly if you enabled Clientless VPN.

There is no availability impact to GlobalProtect features or GlobalProtect users. Attackers cannot use this vulnerability to tamper with or modify contents or configurations of the GlobalProtect portal or gateways. The integrity impact of this vulnerability is limited to enabling an attacker to create phishing and credential-stealing links that appear to be hosted on the GlobalProtect portal.

For GlobalProtect users with Clientless VPN enabled, there is a limited impact on confidentiality due to inherent risks of Clientless VPN that facilitate credential theft. You can read more about this risk in the informational bulletin PAN-SA-2025-0005 https://security.paloaltonetworks.com/PAN-SA-2025-0005 https://security.paloaltonetworks.com/PAN-SA-2025-0005 . There is no impact to confidentiality for GlobalProtect users if you did not enable (or you disable) Clientless VPN.

Other sources

A reflected cross-site scripting (XSS) vulnerability in the GlobalProtect™ gateway and portal features of Palo Alto Networks PAN-OS® software enables execution of malicious JavaScript in the context of an authenticated Captive Portal user's browser when they click on a specially crafted link. The primary risk is phishing attacks that can lead to credential theft—particularly if you enabled Clientless VPN.

There is no availability impact to GlobalProtect features or GlobalProtect users. Attackers cannot use this vulnerability to tamper with or modify contents or configurations of the GlobalProtect portal or gateways. The integrity impact of this vulnerability is limited to enabling an attacker to create phishing and credential-stealing links that appear to be hosted on the GlobalProtect portal.

For GlobalProtect users with Clientless VPN enabled, there is a limited impact on confidentiality due to inherent risks of Clientless VPN that facilitate credential theft. You can read more about this risk in the informational bulletin PAN-SA-2025-0005 (https://security.paloaltonetworks.com/PAN-SA-2025-0005)https://security.paloaltonetworks.com/PAN-SA-2025-0005. There is no impact to confidentiality for GlobalProtect users if you did not enable (or you disable) Clientless VPN.

Palo Alto Networks

Affected Software

4 affected componentsFixes available
Palo Alto Networks PAN-OS
Palo Alto Networks Cloud NGFW
Palo Alto Networks PAN-OS<11.2.7, =11.2.0, =11.1.0, =10.2.0, =10.1.0
11.2.711.2.4-h911.1.10-h111.1.6-h1410.2.16-h1
Palo Alto Networks Prisma Access

Remediation

Mitigation

Customers with a Threat Prevention subscription can block attacks for this vulnerability by enabling Threat ID 510003 and 510004 from Applications and Threats content version 8995. For all Cloud NGFW, PAN-OS, and Prisma Access deployments, it is crucial to ensure that Vulnerability Protection profiles are explicitly applied to the security rules that process traffic from GlobalProtect interfaces. This ensures the Threat Prevention signatures are actively enforced. For detailed guidance on applying Vulnerability Protection to GlobalProtect interfaces, please refer to: https://live.paloaltonetworks.com/t5/globalprotect-articles/applying-vulnerability-protection-to-globalprotect-interfaces/ta-p/340184. You can also disable Clientless VPN to reduce impact in the event of exploitation, though this will not block the exploit in it's entirety. For more information, review the security advisory PAN-SA-2025-0005 (https://security.paloaltonetworks.com/PAN-SA-2025-0005). Previous versions of this advisory have listed the recommended content version as 8970 and 8990. We now recommend 8995 as it has the latest updates to the signatures to cover additional exploit variants. 

Information

VERSION MINOR VERSION SUGGESTED SOLUTION PAN-OS 11.2 11.2.0 through 11.2.4 Upgrade to 11.2.4-h9 or later   11.2.5 through 11.2.6 Upgrade to 11.2.7 or later PAN-OS 11.1 11.1.0 through 11.1.6 Upgrade to 11.1.6-h14 or later   11.1.7 through 11.1.10 Upgrade to 11.1.10-h1 or later PAN-OS 10.2 10.2.0 through 10.2.16 Upgrade to 10.2.16-h1 or later PAN-OS 10.1 10.1.0 through 10.1.14 Upgrade to 10.2.16-h1 or later All other older unsupported PAN-OS versions Upgrade to a supported fixed version PAN-OS 10.1 is in L (https://www.paloaltonetworks.com/services/support/end-of-life-announcements/end-of-life-policy)imited Support (https://www.paloaltonetworks.com/services/support/end-of-life-announcements/end-of-life-policy) and reaches Software EOL (https://www.paloaltonetworks.com/services/support/end-of-life-announcements/end-of-life-summary)in March 2026. https://www.paloaltonetworks.com/services/support/end-of-life-announcements/end-of-life-policy

Event History

May 14, 2025
Advisory Published
via Palo Alto Networks·04:00 PM
Data Sourced
via Palo Alto Networks·04:00 PM
RemedyDescriptionSeverityWeaknessAffected Software
CVE Published
via MITRE·06:07 PM
Data Sourced
via MITRE·06:07 PM
DescriptionWeakness
Data Sourced
via NVD·07:15 PM
DescriptionSeverityWeakness
Jul 9, 2025
Advisory Published
via Palo Alto Networks·04:00 PM
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2025-0133?

CVE-2025-0133 has been classified as a medium severity vulnerability.

2

How do I fix CVE-2025-0133?

To remediate CVE-2025-0133, upgrade to PAN-OS versions 11.2.8, 11.1.11, or 10.2.17.

3

Who is affected by CVE-2025-0133?

CVE-2025-0133 affects users of the GlobalProtect gateway and portal features in Palo Alto Networks PAN-OS software.

4

What type of vulnerability is CVE-2025-0133?

CVE-2025-0133 is a reflected cross-site scripting (XSS) vulnerability.

5

What can attackers achieve by exploiting CVE-2025-0133?

Exploitation of CVE-2025-0133 allows attackers to execute malicious JavaScript in the context of an authenticated user's browser.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203