CVE-2025-0136: PAN-OS: Unencrypted Data Transfer when using AES-128-CCM on Intel-based hardware devices (Severity: LOW)
Using the AES-128-CCM algorithm for IPSec on certain Palo Alto Networks PAN-OS® firewalls (PA-7500, PA-5400, PA-5400f, PA-3400, PA-1400, and PA-400 Series) leads to unencrypted data transfer to devices that are connected to the PAN-OS firewall through IPSec.
This issue does not affect Cloud NGFWs, Prisma® Access instances, or PAN-OS VM-Series firewalls.
NOTE: The AES-128-CCM encryption algorithm is not recommended for use.
Other sources
Using the AES-128-CCM algorithm for IPSec on certain Palo Alto Networks PAN-OS® firewalls (PA-7500, PA-5400, PA-5400f, PA-3400, PA-1600, PA-1400, and PA-400 Series) leads to unencrypted data transfer to devices that are connected to the PAN-OS firewall through IPSec.
This issue does not affect Cloud NGFWs, Prisma® Access instances, or PAN-OS VM-Series firewalls.
NOTE: The AES-128-CCM encryption algorithm is not recommended for use.
— MITRE
Affected Software
Remediation
Mitigation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-0136?
CVE-2025-0136 has not been assigned a specific severity score but involves the potential for unencrypted data transfer in certain Palo Alto Networks PAN-OS firewalls.
How do I fix CVE-2025-0136?
To mitigate CVE-2025-0136, upgrade to PAN-OS versions 10.1.14-h14, 10.2.11, 11.0.7, or 11.1.5 or later.
Which Palo Alto Networks products are affected by CVE-2025-0136?
CVE-2025-0136 affects Palo Alto Networks PAN-OS firewalls including PA-7500, PA-5400, PA-3400, and PA-400 Series models.
What type of vulnerability is CVE-2025-0136?
CVE-2025-0136 is a vulnerability related to the AES-128-CCM algorithm used for IPSec leading to potential unencrypted data transmission.
When was CVE-2025-0136 reported?
CVE-2025-0136 was reported as a security vulnerability affecting specific versions of Palo Alto Networks PAN-OS.