
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-4227 is an improper access control vulnerability in the Endpoint Traffic Policy Enforcement feature of the Palo Alto Networks GlobalProtect™ app that allows certain network packets to remain unencrypted instead of being properly secured within the VPN tunnel. It affects GlobalProtect App versions 6.0.x and 6.1.x (all builds on Windows/macOS), 6.2.0–6.2.8-c223, and 6.3.0–6.3.3 on Windows and macOS; Linux, Android, iOS, Chrome OS, and UWP platforms are unaffected as they do not include the Endpoint Traffic Policy Enforcement feature. The vulnerability was published on June 11, 2025, and updated on June 13, 2025. It carries a CVSS v3.1 base score of 3.5 (Low) and a CVSS v4.0 base score of 1.0 (Low) (Palo Alto Advisory).
The root cause is classified as CWE-319 (Cleartext Transmission of Sensitive Information): under certain conditions, the Endpoint Traffic Policy Enforcement feature fails to enforce proper access controls, allowing packets to bypass VPN tunnel encryption and be transmitted in cleartext. Exploitation requires an attacker with physical access to the network segment who can insert a rogue device to intercept the unencrypted packets — a scenario mapped to CAPEC-117 (Interception). The vulnerability is only triggered when the Endpoint Traffic Policy Enforcement feature is enabled (set to any option other than "No") in the GlobalProtect portal configuration. Notably, the GlobalProtect app automatically recovers from the interception state within approximately one minute under normal operating conditions (Palo Alto Advisory).
An attacker with physical network access who successfully exploits this vulnerability can intercept unencrypted packets during the brief window before the GlobalProtect app self-recovers, resulting in limited confidentiality and integrity impact on network communications. The exposure is constrained to the local network segment, requires physical presence, and the self-recovery mechanism limits the interception window to roughly one minute. There is no availability impact, no remote exploitation vector, and no potential for lateral movement or privilege escalation beyond packet interception (Palo Alto Advisory).
No public proof-of-concept exploit code exists, and Palo Alto Networks has confirmed no known malicious exploitation of this issue in the wild. The EPSS score is approximately 0.015% (0.000150), reflecting very low probability of exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation is non-automatable, requires physical network access, and depends on the Endpoint Traffic Policy Enforcement feature being enabled — significantly limiting the realistic attacker population (Palo Alto Advisory).
Palo Alto Networks recommends a multi-step remediation process. First, upgrade the GlobalProtect App to version 6.2.8-c243 (or later) or 6.3.3-c650 (or later) on all affected Windows and macOS endpoints. Second, set "Endpoint Traffic Policy Enforcement" to "All Traffic" in the GlobalProtect portal configuration (Network > GlobalProtect > Portals > Agent > App > App Configurations). Third, enable "Allow Gateway Access from GlobalProtect Only" (requires Content version 8977 or newer) in the same configuration path. For environments using Autonomous Digital Experience Management (ADEM) — where ICMP probes must travel outside the tunnel — set Endpoint Traffic Policy Enforcement to "All TCP/UDP Traffic" instead of "All Traffic" as a partial mitigation, noting that ICMP and other non-TCP/UDP traffic may still be interceptable. Additionally, enforce strict physical access controls on network infrastructure (Palo Alto Advisory).
The vulnerability was reported externally by Tan Cheng Ghee of OCBC Bank and acknowledged by Palo Alto Networks in their advisory. Coverage was picked up by security news outlets including Heise (noting it alongside other Palo Alto patches) and aggregated by security databases such as Red Packet Security, Tenable, and HKCERT. Given the low severity rating and physical access requirement, community reaction has been muted, with no significant controversy or widespread concern noted (Palo Alto Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."