GlobalProtect App: Improper Certificate Validation Bypass Vulnerability
Improper certificate validation in Palo Alto Networks GlobalProtect app on Windows, macOS, and Linux allows an unauthenticated attacker with man-in-the-middle access to intercept and modify application communications. An attacker positioned on the network path between a user's device and the Palo Alto gateway can present a fraudulent certificate and capture credentials or session tokens. VPN tunnel traffic is not impacted. iOS, Android, and Chrome OS versions are not affected. Multiple fixed versions are available depending on platform and current version: 6.3.3-h15 (Linux), 6.3.3-h14 / 6.3.3-1121 (macOS and Windows), 6.2.8-h13 / 6.2.8-1045 (macOS and Windows), and 6.0.15 (all platforms). Note that GlobalProtect App on Linux with version below 6.3.3-h15 is mentioned with a note that not all Linux versions have a fix available.
- Attacker positioned on the network path between the user's device and the Palo Alto gateway (same WiFi, compromised router, etc.)
- Vulnerable version of GlobalProtect app installed on Windows, macOS, or Linux (iOS, Android, Chrome OS not affected)
- User initiates a connection to the VPN before connecting to the VPN tunnel
Patching may require device reboot — plan for process interruption
/api/v1/advisories/aa4dc82f-3568-4d03-be23-3735272419c3Get OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.