Insufficient Certificate Validation in Palo Alto Networks GlobalProtect App
CVE-2025-2183
Key Information:
- Vendor
Palo Alto Networks
- Vendor
- CVE Published:
- 13 August 2025
Badges
What is CVE-2025-2183?
The vulnerability in the Palo Alto Networks GlobalProtect app arises from insufficient certificate validation, allowing attackers to connect the app to unauthorized servers. This risk primarily affects local non-administrative users or any attacker sharing the same network segment, enabling the potential installation of malicious root certificates on compromised endpoints. If successfully exploited, this could lead to the installation of malicious software signed by these root certificates, thereby jeopardizing the security and integrity of the affected systems.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
GlobalProtect App Linux 6.3.0 < 6.3.3
GlobalProtect App Linux 6.2.0 < 11.1.10
GlobalProtect App Linux 6.1.0
References
CVSS V4
Timeline
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved