CVE-2025-4614: PAN-OS: Session Token Disclosure Vulnerability (Severity: LOW)
An information disclosure vulnerability in Palo Alto Networks PAN-OS® software enables an authenticated administrator to view session tokens of users authenticated to the firewall web UI. This may allow impersonation of users whose session tokens are leaked.
The security risk posed by this issue is significantly minimized when CLI access is restricted to a limited group of administrators.
Cloud NGFW and Prisma® Access are not affected by this vulnerability.
Affected Software
Remediation
Mitigation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-4614?
CVE-2025-4614 is classified as an information disclosure vulnerability that poses a risk of user impersonation.
How do I fix CVE-2025-4614?
To resolve CVE-2025-4614, upgrade PAN-OS to versions 10.2.18, 11.1.13, or 11.2.9 or later.
Who is affected by CVE-2025-4614?
CVE-2025-4614 affects users of Palo Alto Networks PAN-OS, Cloud NGFW, and Prisma Access software.
What can attackers do with CVE-2025-4614?
Attackers exploiting CVE-2025-4614 can potentially impersonate legitimate users by accessing their session tokens.
Is CVE-2025-4614 remotely exploitable?
CVE-2025-4614 requires authenticated access, meaning it is not remotely exploitable without valid credentials.