Home
LOW: 2.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/AU:N/R:U/V:D/RE:M/U:AmberDefault status
unaffected
1 (custom) before 34.01.129
affected
Default status
unaffected
All (custom)
unaffected
Description
Web sessions in the web interface of Palo Alto Networks Prisma® Cloud Compute Edition do not expire when users are deleted, which makes Prisma Cloud Compute Edition susceptible to unauthorized access. Compute in Prisma Cloud Enterprise Edition is not affected by this issue.
Problem types
CWE-613 Insufficient Session Expiration
Product status
1 (custom) before 34.01.129
All (custom)
Timeline
| 2025-05-14: | Initial Publication |
Credits
Maciej Pypec of ING
References
security.paloaltonetworks.com/CVE-2025-0138