CVE-2025-2182

PAN-OS: Firewall Clusters using the MACsec Protocol Expose the Connectivity Association Key (CAK)

Severity
Medium 5.6
CVSS 4.0
Exploited
Not listed
EPSS
0.001
1.9th percentile
Discovered by
Vendor
Vendor-published field
Published
Aug 13, 2025
Assigned by palo_alto

Description

A problem with the implementation of the MACsec protocol in Palo Alto Networks PAN-OS® results in the cleartext exposure of the connectivity association key (CAK). This issue is only applicable to PA-7500 Series devices which are in an NGFW cluster. A user who possesses this key can read messages being sent between devices in a NGFW Cluster. There is no impact in non-clustered firewalls or clusters of firewalls that do not enable MACsec.

Weakness: CWE-312

Affected products

Vendor Product Category Matched by
Palo Alto Networks PAN-OS Firewall / NGFW cna-assigner
Vendor-reported products (4)
  • Palo Alto Networks · Cloud NGFW — vendor states not affected
  • Palo Alto Networks · PAN-OS
  • Palo Alto Networks · PAN-OS — vendor states not affected
  • Palo Alto Networks · Prisma Access — vendor states not affected

Credit

This issue was found during an internal security review.

Vendor remediation

Version Minor Version Suggested Solution Cloud NGFW No action needed. PAN-OS 11.2 on PA-7500 11.2.0 through 11.2.7 Upgrade to 11.2.8 or later. PAN-OS 11.1 on PA-7500 11.1.0 through 11.1.9 Upgrade to 11.1.10 or later. PAN-OS 10.2 on PA-7500 No action needed.PAN-OS 10.1 on PA-7500 No action needed.PAN-OS on devices other than PA-7500 No action needed.All older unsupported PAN-OS versions Upgrade to a supported fixed version.Prisma Access No action needed.

Something wrong here?