CVE-2025-0122: Prisma SD-WAN: Denial of Service (DoS) Vulnerability Through Burst of Crafted Packets (Severity: MEDIUM)
Published Apr 9, 2025
·Updated
A denial-of-service (DoS) vulnerability in Palo Alto Networks Prisma® SD-WAN ION devices enables an unauthenticated attacker in a network adjacent to a Prisma SD-WAN ION device to disrupt the packet processing capabilities of the device by sending a burst of crafted packets to that device.
Affected Software
2 affected componentsFixes available
Prisma SD-WAN
Palo Alto Networks Prisma SD-WAN<6.5.1, =6.5.0, <6.4.2, =6.4.0, <6.3.4, =6.3.0, =6.2.0, <6.1.10, =6.1.0, =5.6.0
6.5.16.4.26.3.46.1.10
Remediation
Mitigation
There are no known workarounds for this issue.
Information
VERSION SUGGESTED SOLUTION
Prisma SD-WAN 6.5 Upgrade to Prisma SD-WAN 6.5.1 or later
Prisma SD-WAN 6.4 Upgrade to Prisma SD-WAN 6.4.2 or later
Prisma SD-WAN 6.3 Upgrade to Prisma SD-WAN 6.3.4 or later
Prisma SD-WAN 6.2 Upgrade to Prisma SD-WAN 6.3.4 or later
Prisma SD-WAN 6.1 Upgrade to Prisma SD-WAN 6.1.10 or later
Prisma SD-WAN 5.6 Upgrade to Prisma SD-WAN 6.3.4 or later
Event History
Apr 9, 2025
Advisory Published
via Palo Alto Networks·04:00 PM
Apr 11, 2025
CVE Published
via MITRE·01:48 AM
Data Sourced
via MITRE·01:48 AM
DescriptionWeakness
Data Sourced
via NVD·02:15 AM
DescriptionSeverityWeakness
Apr 15, 2025
Advisory Published
via Palo Alto Networks·09:15 PM
Frequently Asked Questions
1
What is the severity of CVE-2025-0122?
CVE-2025-0122 has been classified as a denial-of-service vulnerability.
2
How do I fix CVE-2025-0122?
To mitigate CVE-2025-0122, upgrade Prisma SD-WAN to versions 6.5.1, 6.4.2, 6.3.4, or 6.1.10.
3
Who is affected by CVE-2025-0122?
CVE-2025-0122 affects Palo Alto Networks Prisma SD-WAN ION devices.
4
What could an attacker do using CVE-2025-0122?
An attacker could disrupt the packet processing capabilities of affected devices by sending crafted packets.
5
Is authentication required to exploit CVE-2025-0122?
No, CVE-2025-0122 can be exploited by an unauthenticated attacker.