CVE Database
/

CVE-2025-2183

Back to search

CVE-2025-2183

Published: Aug 13, 2025

Modified: Feb 26, 2026

PUBLISHED

Description

An insufficient certificate validation issue in the Palo Alto Networks GlobalProtect™ app enables attackers to connect the GlobalProtect app to arbitrary servers. This can enable a local non-administrative operating system user or an attacker on the same subnet to install malicious root certificates on the endpoint and subsequently install malicious software signed by the malicious root certificates on that endpoint.

VendorProductVersions

Palo Alto Networks

GlobalProtect App

affected
6.3.0 - < 6.3.3-h2 (6.3.3-c676)
affected
6.2.0 - < 6.2.8-h3 (6.2.8-c263)
affected
6.1.0
affected
6.0.0

Palo Alto Networks

GlobalProtect App

affected
6.3.0 - < 6.3.3
affected
6.2.0 - < 11.1.10
affected
6.1.0
affected
6.0.0

Palo Alto Networks

GlobalProtect App

unaffected
All

Palo Alto Networks

Global Protect UWP App

unaffected
All

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now
CVE-2025-2183 - Security Vulnerability | QwikSec