CVE-2025-4615
PAN-OS Analyse et atténuation des vulnérabilités

Aperçu

An improper input neutralization vulnerability (CVE-2025-4615) was discovered in the management web interface of the Palo Alto Networks PAN-OS software. The vulnerability was disclosed on October 8, 2025, affecting multiple versions of PAN-OS including versions prior to 11.2.8, 11.1.11, and 10.2.17. This security issue enables an authenticated administrator to bypass system restrictions and execute arbitrary commands (Palo Security). Cloud NGFW and Prisma Access are not affected by this vulnerability.

Détails techniques

The vulnerability is classified as CWE-83 (Improper Neutralization of Script in Attributes in a Web Page) with a CVSS v4.0 base score of 7.0 (HIGH) when exposed to external IP addresses, and 4.5 (MEDIUM) when access is restricted. The attack vector is classified as adjacent network with low attack complexity, requiring high privileges but no user interaction. The vulnerability impacts system integrity and availability while maintaining system confidentiality (NVD).

Impact

The vulnerability allows authenticated administrators to execute arbitrary commands through the management web interface, potentially compromising system integrity and availability. The security risk is significantly minimized when CLI access is restricted to a limited group of administrators (Palo Security).

Atténuation et solutions de contournement

Palo Alto Networks has released patches for affected versions. Users should upgrade to PAN-OS version 11.2.8 or later, 11.1.11 or later, or 10.2.17 or later, depending on their current version. The risk can be significantly reduced by restricting access to a jump box that is the only system allowed to access the management interface (ASEC, Palo Security).

Réactions de la communauté

The vulnerability was discovered and reported by Visa Inc., demonstrating collaborative security research within the industry. Palo Alto Networks has recommended addressing this vulnerability during the next scheduled maintenance cycle for environments with restricted management interface access (Palo Security).

Ressources additionnelles


SourceCe rapport a été généré à l’aide de l’IA

Apparenté PAN-OS Vulnérabilités:

Identifiant CVE

Sévérité

Score

Technologies

Nom du composant

Exploit CISA KEV

A corrigé

Date de publication

CVE-2026-0300CRITICAL9.3
  • PAN-OSPAN-OS
  • cpe:2.3:o:paloaltonetworks:pan-os
OuiOuiMay 06, 2026
CVE-2025-4231HIGH8.6
  • PAN-OSPAN-OS
  • cpe:2.3:o:paloaltonetworks:pan-os
NonOuiJun 13, 2025
CVE-2026-0227MEDIUM6.6
  • PAN-OSPAN-OS
  • cpe:2.3:o:paloaltonetworks:pan-os
NonOuiJan 15, 2026
CVE-2025-4615MEDIUM5.5
  • PAN-OSPAN-OS
  • cpe:2.3:o:paloaltonetworks:pan-os
NonOuiOct 09, 2025
CVE-2025-4614MEDIUM4.8
  • PAN-OSPAN-OS
  • cpe:2.3:o:paloaltonetworks:pan-os
NonOuiOct 09, 2025

Évaluation gratuite des vulnérabilités

Évaluez votre posture de sécurité dans le cloud

Évaluez vos pratiques de sécurité cloud dans 9 domaines de sécurité pour évaluer votre niveau de risque et identifier les failles dans vos défenses.

Demander une évaluation

Obtenez une démo personnalisée

Prêt(e) à voir Wiz en action ?

"La meilleure expérience utilisateur que j’ai jamais vue, offre une visibilité totale sur les workloads cloud."
David EstlickRSSI
"Wiz fournit une interface unique pour voir ce qui se passe dans nos environnements cloud."
Adam FletcherChef du service de sécurité
"Nous savons que si Wiz identifie quelque chose comme critique, c’est qu’il l’est réellement."
Greg PoniatowskiResponsable de la gestion des menaces et des vulnérabilités