CVE 4.8 MEDIUM

PAN-OS: Session Token Disclosure Vulnerability_CVE-2025-4614

4.8 / 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N/AU:N/R:U/V:C/RE:M/U:Amber

Description

An information disclosure vulnerability in Palo Alto Networks PAN-OS® software enables an authenticated administrator to view session tokens of users authenticated to the firewall web UI. This may allow impersonation of users whose session tokens are leaked.  

The security risk posed by this issue is significantly minimized when CLI access is restricted to a limited group of administrators.

Cloud NGFW and Prisma® Access are not affected by this vulnerability.

Basic Information

ID CVE-2025-4614
Source palo_alto
Published Oct 9, 2025 at 18:13
Modified Oct 9, 2025 at 19:15

Affected Product

Vendor Palo Alto Networks
Product Cloud NGFW
Version All
Affected Versions Palo Alto Networks PAN-OS 11.2.0
Palo Alto Networks PAN-OS 11.1.0
Palo Alto Networks PAN-OS 10.2.0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.