CVE-2025-4230: PAN-OS: Authenticated Admin Command Injection Vulnerability Through CLI
A command injection vulnerability in Palo Alto Networks PAN-OS® software enables an authenticated administrator to bypass system restrictions and run arbitrary commands as a root user. To be able to exploit this issue, the user must have access to the PAN-OS CLI.
The security risk posed by this issue is significantly minimized when CLI access is restricted to a limited group of administrators.
Cloud NGFW and Prisma® Access are not affected by this vulnerability.
Affected Software
Remediation
Mitigation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-4230?
CVE-2025-4230 is rated as a high severity vulnerability due to its capability to allow command injection and remote execution of arbitrary commands.
How do I fix CVE-2025-4230?
To mitigate CVE-2025-4230, ensure your Palo Alto Networks PAN-OS is updated to a version that is not affected by this vulnerability, specifically versions later than 11.2.6, 11.1.10, 10.2.14, and 10.1.14-h15.
Who is affected by CVE-2025-4230?
CVE-2025-4230 impacts authenticated administrators of Palo Alto Networks PAN-OS software who have access to the command line interface.
What products are impacted by CVE-2025-4230?
Products affected by CVE-2025-4230 include Palo Alto Networks PAN-OS, Cloud NGFW, and Prisma Access.
What type of vulnerability is CVE-2025-4230?
CVE-2025-4230 is classified as a command injection vulnerability, which allows unauthorized command execution under certain conditions.