CVE-2025-0122

Prisma SD-WAN: Denial of Service (DoS) Vulnerability Through Burst of Crafted Packets

Severity
Medium 5.1
CVSS 4.0
Exploited
Not listed
EPSS
0.003
17.8th percentile
Discovered by
Vendor
Published by the vendor
Published
Apr 11, 2025
Assigned by palo_alto

Description

A denial-of-service (DoS) vulnerability in Palo Alto Networks Prisma® SD-WAN ION devices enables an unauthenticated attacker in a network adjacent to a Prisma SD-WAN ION device to disrupt the packet processing capabilities of the device by sending a burst of crafted packets to that device.

Weakness: CWE-770

Affected products

Vendor Product Category Matched by
Palo Alto Networks Prisma SD-WAN SASE / SSE / Secure Web cna-assigner
Vendor-reported affected versions (1)
  • Palo Alto Networks · Prisma SD-WAN

Credit

Vajrapu Venkata Sarat Kumar of Palo Alto Networks

Vendor remediation

VersionSuggested SolutionPrisma SD-WAN 6.5Upgrade to Prisma SD-WAN 6.5.1 or laterPrisma SD-WAN 6.4 Upgrade to Prisma SD-WAN 6.4.2 or laterPrisma SD-WAN 6.3Upgrade to Prisma SD-WAN 6.3.4 or laterPrisma SD-WAN 6.2Upgrade to Prisma SD-WAN 6.3.4 or laterPrisma SD-WAN 6.1Upgrade to Prisma SD-WAN 6.1.10 or later