针对启用了Clientless VPN的GlobalProtect用户,由于Clientless VPN固有的风险,存在凭据被盗的潜在风险,可能对机密性产生有限的影响。如果未启用Clientless VPN,则GlobalProtect用户不受影响。该问题仅适用于启用了GlobalProtect网关或Portal的PAN-OS防火墙配置。建议用户启用威胁防御订阅,并开启Threat ID 510003和510004(在Applications and Threats内容版本8970中引入)来阻止攻击。此外,也可以选择禁用Clientless VPN。
For GlobalProtect users with Clientless VPN enabled, there is a limited impact on confidentiality due to inherent risks of Clientless VPN that facilitate credential theft. You can read more about this risk in the informational bulletin PAN-SA-2025-0005. There is no impact to confidentiality for GlobalProtect users if you did not enable (or you disable) Clientless VPN.
This issue is applicable only to PAN-OS firewall configurations with an enabled GlobalProtect gateway or portal.
Customers with a Threat Prevention subscription can block attacks for this vulnerability by enabling Threat ID 510003 and 510004 (introduced in Applications and Threats content version 8970).
You can also disable Clientless VPN. For more information, review the security advisory PAN-SA-2025-0005.