Description
An information disclosure vulnerability in the SD-WAN feature of Palo Alto Networks PAN-OS® software enables an unauthorized user to view unencrypted data sent from the firewall through the SD-WAN interface. This requires the user to be able to intercept packets sent from the firewall. Cloud NGFW and Prisma® Access are not affected by this vulnerability.
Problem types
CWE-497 Exposure of Sensitive System Information to an Unauthorized Control Sphere
Product status
All (custom)
11.2.0 (custom) before 11.2.7
11.1.0 (custom) before 11.1.10
10.2.0 (custom) before 10.2.17
10.1.0 (custom) before 10.1.14-h16
All (custom)
Timeline
| 2025-06-11: | Initial Publication |
Credits
MMS Technology
References
security.paloaltonetworks.com/CVE-2025-4229