CVE-2025-4229

PAN-OS: Traffic Information Disclosure Vulnerability

Severity
Medium 6
CVSS 4.0
Exploited
Not listed
EPSS
0.004
35.4th percentile
Discovered by
Third party
Published by the vendor
Published
Jun 13, 2025
Assigned by palo_alto

Description

An information disclosure vulnerability in the SD-WAN feature of Palo Alto Networks PAN-OS® software enables an unauthorized user to view unencrypted data sent from the firewall through the SD-WAN interface. This requires the user to be able to intercept packets sent from the firewall. Cloud NGFW and Prisma® Access are not affected by this vulnerability.

Weakness: CWE-497

Affected products

Vendor Product Category Matched by
Palo Alto Networks Cloud NGFW Firewall / NGFW cna-assigner
Palo Alto Networks PAN-OS Firewall / NGFW cna-assigner
Palo Alto Networks Prisma Access SASE / SSE / Secure Web cna-assigner
Vendor-reported affected versions (3)
  • Palo Alto Networks · Cloud NGFW
  • Palo Alto Networks · PAN-OS
  • Palo Alto Networks · Prisma Access

Credit

MMS Technology

Vendor remediation

Version Minor Version Suggested Solution Cloud NGFW All No action needed. PAN-OS 11.2 11.2.0 through 11.2.6 Upgrade to 11.2.7 or later. PAN-OS 11.1 11.1.0 through 11.1.9 Upgrade to 11.1.10 or later. PAN-OS 10.2 10.2.0 through 10.2.16 Upgrade to 10.2.17 or later. PAN-OS 10.1 10.1.0 through 10.1.14 Upgrade to 10.1.14-h16 or later. All older unsupported PAN-OS versions Upgrade to a supported fixed version.Prisma Access All No action needed.