CVE-2012-4043: Palo Alto Global Protected Gateway

Medium severity, CVSS 4.3. EPSS: 1.4% chance of exploitation in the next 30 days.

Cross-site scripting (XSS) vulnerability in global-protect/login.esp in Palo Alto Networks Global Protect Portal, Global Protect Gateway, and SSL VPN portals 3.1.x through 3.1.11 and 4.0.x through 4.0.5 allows remote attackers to inject arbitrary web script or HTML via the inputStr parameter in a Login action.

Affected products

  • Palo Alto Global Protected Gateway: version 3.1 only; version 3.1.11 only; version 4.0 only; version 4.0.5 only
  • Palo Alto Networks: version global_protect_portal only
  • Palo Alto SSL VPN: version 3.1 only; version 3.1.11 only; version 4.0 only; version 4.0.5 only

Published 2012-07-26. Last modified 2026-06-16.