Description
A problem with the implementation of the MACsec protocol in Palo Alto Networks PAN-OS® results in the cleartext exposure of the connectivity association key (CAK). This issue is only applicable to PA-7500 Series devices which are in an NGFW cluster. A user who possesses this key can read messages being sent between devices in a NGFW Cluster. There is no impact in non-clustered firewalls or clusters of firewalls that do not enable MACsec.
Problem types
CWE-312 Cleartext Storage of Sensitive Information
Product status
All before 3.2.449
11.2.0 before 11.2.8
11.1.0 before 11.1.10
10.2.0
10.1.0
All
All
Timeline
2025-08-13: | Initial Publication |
Credits
This issue was found during an internal security review.
References
security.paloaltonetworks.com/CVE-2025-2182