CVE-2025-4230

PAN-OS: Authenticated Admin Command Injection Vulnerability Through CLI

Severity
High 8.4
CVSS 4.0
Exploited
Not listed
EPSS
0.006
48.5th percentile
Discovered by
Third party
Vendor-published field
Published
Jun 12, 2025
Assigned by palo_alto

Description

A command injection vulnerability in Palo Alto Networks PAN-OS® software enables an authenticated administrator to bypass system restrictions and run arbitrary commands as a root user. To be able to exploit this issue, the user must have access to the PAN-OS CLI. The security risk posed by this issue is significantly minimized when CLI access is restricted to a limited group of administrators. Cloud NGFW and Prisma® Access are not affected by this vulnerability.

Weakness: CWE-78

Affected products

Vendor Product Category Matched by
Palo Alto Networks PAN-OS Firewall / NGFW cna-assigner
Vendor-reported products (3)
  • Palo Alto Networks · Cloud NGFW — vendor states not affected
  • Palo Alto Networks · PAN-OS
  • Palo Alto Networks · Prisma Access — vendor states not affected

Credit

Visa Inc.

Vendor remediation

Version Minor Version Suggested Solution Cloud NGFW All No action needed. PAN-OS 11.2 11.2.0 through 11.2.5 Upgrade to 11.2.6 or later. PAN-OS 11.1 11.1.0 through 11.1.9 Upgrade to 11.1.10 or later. PAN-OS 10.2 10.2.0 through 10.2.13 Upgrade to 10.2.14 or later. PAN-OS 10.1 10.1.0 through 10.1.14 Upgrade to 10.1.14-h15 or later. All older unsupported PAN-OS versions Upgrade to a supported fixed version.Prisma Access All No action needed.

Something wrong here?