CVE-2025-4231: PAN-OS: Authenticated Admin Command Injection Vulnerability in the Management Web Interface (Severity: MEDIUM)
A command injection vulnerability in Palo Alto Networks PAN-OS® enables an authenticated administrative user to perform actions as the root user.
The attacker must have network access to the management web interface and successfully authenticate to exploit this issue.
Cloud NGFW and Prisma Access are not impacted by this vulnerability.
Affected Software
Remediation
Mitigation
Information
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-4231?
CVE-2025-4231 is classified as a high-severity command injection vulnerability.
Who can exploit CVE-2025-4231?
Only authenticated administrative users with network access to the management web interface can exploit CVE-2025-4231.
How do I fix CVE-2025-4231?
To mitigate CVE-2025-4231, upgrade to the patched versions of PAN-OS 11.0.4, 10.2.9, or later as specified by Palo Alto Networks.
What products are affected by CVE-2025-4231?
CVE-2025-4231 affects Palo Alto Networks Cloud NGFW, PAN-OS versions up to 11.0.3 and 10.2.8, as well as Prisma Access.
What type of vulnerability is CVE-2025-4231?
CVE-2025-4231 is a command injection vulnerability that allows unauthorized actions to be performed as the root user.