CVE-2025-0138
Prisma Cloud Compute Edition: Insufficient Session Expiration Vulnerability in the Web Interface
Severity
Low 2
CVSS 4.0
Exploited
Not listed
EPSS
0.003
25.1th percentile
Discovered by
Third party
Published by the vendor
Published
May 14, 2025
Assigned by palo_alto
Description
Web sessions in the web interface of Palo Alto Networks Prisma® Cloud Compute Edition do not expire when users are deleted, which makes Prisma Cloud Compute Edition susceptible to unauthorized access. Compute in Prisma Cloud Enterprise Edition is not affected by this issue.
Weakness: CWE-613
Affected products
| Vendor | Product | Category | Matched by |
|---|---|---|---|
| Palo Alto Networks | Prisma Cloud | Cloud Security | cna-assigner |
Vendor-reported affected versions (2)
- Palo Alto Networks · Prisma Cloud Compute Edition
- Palo Alto Networks · Compute in Prisma Cloud Enterprise Edition
Credit
Maciej Pypec of ING
Vendor remediation
This issue is fixed in Prisma Cloud Compute Edition 34.01.129, and all later Prisma Cloud Compute Edition versions.