4.8
/ 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N/AU:N/R:U/V:C/RE:M/U:Amber
Description
An information disclosure vulnerability in Palo Alto Networks PAN-OS® software enables an authenticated administrator to view session tokens of users authenticated to the firewall web UI. This may allow impersonation of users whose session tokens are leaked.
The security risk posed by this issue is significantly minimized when CLI access is restricted to a limited group of administrators.
Cloud NGFW and Prisma® Access are not affected by this vulnerability.
The security risk posed by this issue is significantly minimized when CLI access is restricted to a limited group of administrators.
Cloud NGFW and Prisma® Access are not affected by this vulnerability.
Basic Information
ID
CVE-2025-4614
Source
palo_alto
Published
Oct 9, 2025 at 18:13
Modified
Oct 9, 2025 at 19:15
Affected Product
Vendor
Palo Alto Networks
Product
Cloud NGFW
Version
All
Affected Versions
Palo Alto Networks PAN-OS 11.2.0
Palo Alto Networks PAN-OS 11.1.0
Palo Alto Networks PAN-OS 10.2.0
Palo Alto Networks PAN-OS 11.1.0
Palo Alto Networks PAN-OS 10.2.0