Description
Using the AES-128-CCM algorithm for IPSec on certain Palo Alto Networks PAN-OS® firewalls (PA-7500, PA-5400, PA-5400f, PA-3400, PA-1600, PA-1400, and PA-400 Series) leads to unencrypted data transfer to devices that are connected to the PAN-OS firewall through IPSec. This issue does not affect Cloud NGFWs, Prisma® Access instances, or PAN-OS VM-Series firewalls. NOTE: The AES-128-CCM encryption algorithm is not recommended for use.
Problem types
CWE-319 Cleartext Transmission of Sensitive Information
Product status
All (custom)
11.2.0 (custom)
11.1.0 (custom) before 11.1.5
11.0.0 (custom) before 11.0.7
10.2.0 (custom) before 10.2.11
10.1.0 (custom) before 10.1.14-h14
All (custom)
Timeline
| 2025-05-14: | Initial Publication |
Credits
Benjamin Bai of Palo Alto Networks
References
security.paloaltonetworks.com/CVE-2025-0136