CVE-2025-0133 is a reflected cross-site scripting (XSS) vulnerability found in the GlobalProtect gateway and portal features of Palo Alto Networks PAN-OS software. This flaw allows an attacker to execute malicious JavaScript in an authenticated user's browser if they click a specially crafted link, primarily enabling phishing attacks and potential credential theft, especially when Clientless VPN is enabled. Rated with a CVSS score of 2.7 (LOW), the vulnerability requires user interaction and has limited confidentiality and integrity impacts, with no availability impact to GlobalProtect features. There is no evidence of active exploitation, nor is it listed on the CISA KEV catalog, though a Nuclei template for detection exists with minimal community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Palo Alto Networks | PAN-OS | >= 10.2.0, < 10.2.16-h1, >= 11.1.0, < 11.1.6-h14, >= 11.2.0, < 11.2.7, 10.1.0CNA affecteddefault unaffected | |
| Palo Alto Networks | Prisma Access | AllCNA affecteddefault affected | |
| Palo Alto Networks | Cloud NGFW | >= All, < 11.2.8CNA affecteddefault unaffected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:N/R:U/V:D/RE:M/U:Amber
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.