CVE-2025-0133
largeReflected XSS in Palo Alto Networks PAN-OS GlobalProtect Portal and Gateway
CVE-2025-0133 is a reflected cross-site scripting (CWE-79) flaw in the GlobalProtect portal and gateway features of Palo Alto Networks PAN-OS software. It is triggered when an authenticated Captive Portal user clicks a specially crafted link, causing attacker-controlled JavaScript to run in that user's browser. The attacker's gain is limited to phishing: they can make credential-stealing links appear to be hosted on a trusted GlobalProtect portal, with confidentiality impact only for users when Clientless VPN is enabled, and no ability to alter portal/gateway configurations or any availability impact. Affected parties are organizations operating PAN-OS firewalls with the GlobalProtect portal or gateway enabled, particularly those with Clientless VPN turned on. As of the data provided, no public proof-of-concept exists and the flaw is not in CISA's KEV catalog, but EPSS assigns a high 46.4% probability of exploitation within 30 days.
What to do: Upgrade PAN-OS to a patched release per Palo Alto Networks advisory PAN-SA-2025-0005, since the source data does not list specific fixed version numbers. If Clientless VPN is enabled and not needed, disable it to eliminate the confidentiality impact. Confirm whether the GlobalProtect portal or gateway (Captive Portal) is enabled on your firewalls, and warn users not to click unsolicited links that appear to come from the GlobalProtect portal.
| Palo Alto Networks PAN-OS software (GlobalProtect portal and gateway features; confidentiality impact limited to deployments with Clientles | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A reflected cross-site scripting (XSS) vulnerability in the GlobalProtect™ gateway and portal features of Palo Alto Networks PAN-OS® software enables execution of malicious JavaScript in the context of an authenticated Captive Portal user's browser when they click on a specially crafted link. The primary risk is phishing attacks that can lead to credential theft—particularly if you enabled Clientless VPN. There is no availability impact to GlobalProtect features or GlobalProtect users. Attackers cannot use this vulnerability to tamper with or modify contents or configurations of the GlobalProtect portal or gateways. The integrity impact of this vulnerability is limited to enabling an attacker to create phishing and credential-stealing links that appear to be hosted on the GlobalProtect portal. For GlobalProtect users with Clientless VPN enabled, there is a limited impact on confidentiality due to inherent risks of Clientless VPN that facilitate credential theft. You can read more about this risk in the informational bulletin PAN-SA-2025-0005 https://security.paloaltonetworks.com/PAN-SA-2025-0005 https://security.paloaltonetworks.com/PAN-SA-2025-0005 . There is no impact to confidentiality for GlobalProtect users if you did not enable (or you disable) Clientless VPN.
- Weakness
- CWE-79
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:N/R:U/V:D/RE:M/U:Amber
In the news0 stories
No ingested article mentions this CVE yet.