Serious VPN vulnerability found in popular business networking software

VPN
VPN-tjänster har många olika funktioner - här är de allra viktigaste du ska kolla efter. (Image credit: Shutterstock.com)

During an internal security review, Palo Alto Networks discovered an authentication bypass vulnerability in some versions of their PAN-OS software. The vulnerability can be exploited to gain access to restricted VPN network resources.

PAN‑OS is the software that powers all of Palo Alto Networks firewalls products. The vulnerability affects certain versions of four branches of PAN-OS. On PAN-OS 8.1, it affects versions earlier than PAN-OS 8.1.17; on PAN-OS 9.0 versions earlier than PAN-OS 9.0.11; on PAN-OS 9.1 versions earlier than PAN-OS 9.1.5; and on PAN-OS 10.0 versions earlier than PAN-OS 10.0.1.

Even if you are using an affected version, you’re only ath risk if your PAN-OS appliance is set to allow users to authenticate with client certificate authentication.

Stay updated

The authentication bypass issue specifically exists in the GlobalProtect SSL VPN component of PAN-OS. 

For the attack to be successful, your appliance must be running one of the older PAN-OS versions mentioned above. Furthermore, you must have configured the appliance to rely solely on certificate-based authentication. In such a scenario, an attacker could gain access to the network bypassing all client certificate checks.

Palo Alto Networks have tagged the issue as high severity, although it isn’t aware of any malicious exploitation of this issue in the wild.

To mitigate the issue, make sure your appliance is running the newest version of the respective PAN-OS branch. You can also configure the GlobalProtect SSL VPN to require all gateway and portal users to authenticate using their credentials instead of relying on certificates.

Mayank Sharma

With almost two decades of writing and reporting on Linux, Mayank Sharma would like everyone to think he’s TechRadar Pro’s expert on the topic. Of course, he’s just as interested in other computing topics, particularly cybersecurity, cloud, containers, and coding.

Latest in VPN Privacy & Security
Homepage of CloudFlare website on the display of PC, url - CloudFlare.com.
"Network blocking is never going to be the solution" – Cloudflare slams anti-piracy tactics
Panels at RightsCon 2025 during a press briefing about the latest Access Now report of internet shutdowns
2024 was the worst year on record for internet freedoms – again
Vector illustration of the word Censored in a glitch distorted style
Google, Apple, and internet restriction – how Big Tech is making censorship "much worse" according to experts
Google TV onscreen interface showing streaming apps
Why do streaming services geo-restrict content?
Pirate key on computer keyboard
Italy to require VPN and DNS providers to block pirated content
piracy
Canal+ wants to block VPN usage – and VPN providers are fuming
Latest in News
A hand holding a phone showing the Android Find My Device network
Android's Find My Device can now let you track your friends – and I can't decide if that's cool or creepy
Insta360 X4 360 degree camera without lens protector
Leaked DJI Osmo 360 image suggests GoPro and Insta360 should be worried – here's why
A YouTube Premium promo on a laptop screen
A cheaper YouTube Premium Lite plan just rolled out in the US – but you’ll miss out on these 4 features
Viaim RecDot AI true wireless earbuds
These AI-powered earbuds can also act as a dictaphone with transcription when left in their case
The socket interface of the Intel Core Ultra processor
Intel unveils its most powerful AI PCs yet - new Intel Core Ultra Series 2 processors pack in vPro for lightweight laptops and high-performance workstations alike
An Nvidia GeForce RTX 5070
Nvidia confirms that an RTX 5070 Founders Edition is coming... just not on launch day