CVE-2025-4614: PAN-OS: Session Token Disclosure Vulnerability (Severity: LOW)

Published Oct 8, 2025
·
Updated

An information disclosure vulnerability in Palo Alto Networks PAN-OS® software enables an authenticated administrator to view session tokens of users authenticated to the firewall web UI. This may allow impersonation of users whose session tokens are leaked.

The security risk posed by this issue is significantly minimized when CLI access is restricted to a limited group of administrators.

Cloud NGFW and Prisma® Access are not affected by this vulnerability.

Affected Software

18 affected componentsFixes available
Palo Alto Networks Cloud NGFW
Palo Alto Networks PAN-OS<11.2.8, =11.2.0, <11.1.6-h21, =11.1.0, <10.2.17, =10.2.0
11.2.811.1.6-h2110.2.17
Palo Alto Networks Prisma Access
Palo Alto Networks PAN-OS>=10.2.0<10.2.17
Palo Alto Networks PAN-OS>=11.1.0<11.1.6
Palo Alto Networks PAN-OS>=11.2.0<11.2.8
Palo Alto Networks PAN-OS=11.1.6
Palo Alto Networks PAN-OS=11.1.6-h1
Palo Alto Networks PAN-OS=11.1.6-h10
Palo Alto Networks PAN-OS=11.1.6-h14
Palo Alto Networks PAN-OS=11.1.6-h17
Palo Alto Networks PAN-OS=11.1.6-h19
Palo Alto Networks PAN-OS=11.1.6-h20
Palo Alto Networks PAN-OS=11.1.6-h3
Palo Alto Networks PAN-OS=11.1.6-h4
Palo Alto Networks PAN-OS=11.1.6-h5
Palo Alto Networks PAN-OS=11.1.6-h6
Palo Alto Networks PAN-OS=11.1.6-h7

Remediation

Mitigation

There are no known workarounds for this issue.

Information

VERSION MINOR VERSION SUGGESTED SOLUTION Cloud NGFW All No action needed. PAN-OS 12.1 No action needed. PAN-OS 11.2 11.2.0 through 11.2.7 Upgrade to 11.2.8 or later. PAN-OS 11.1 11.1.0 through 11.1.6 Upgrade to 11.1.6-h21 or later. PAN-OS 10.2 10.2.0 through 10.2.16 Upgrade to 10.2.17 or later. All older   Upgrade to a supported fixed version. unsupported PAN-OS versions Prisma Access All No action needed.

Event History

Oct 8, 2025
Advisory Published
via Palo Alto Networks·04:00 PM
Data Sourced
via Palo Alto Networks·04:00 PM
RemedyDescriptionSeverityWeaknessAffected Software
Oct 9, 2025
CVE Published
via MITRE·06:13 PM
Data Sourced
via MITRE·06:13 PM
DescriptionWeakness
Data Sourced
via NVD·07:15 PM
DescriptionSeverityWeaknessAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2025-4614?

CVE-2025-4614 is classified as an information disclosure vulnerability that poses a risk of user impersonation.

2

How do I fix CVE-2025-4614?

To resolve CVE-2025-4614, upgrade PAN-OS to versions 10.2.18, 11.1.13, or 11.2.9 or later.

3

Who is affected by CVE-2025-4614?

CVE-2025-4614 affects users of Palo Alto Networks PAN-OS, Cloud NGFW, and Prisma Access software.

4

What can attackers do with CVE-2025-4614?

Attackers exploiting CVE-2025-4614 can potentially impersonate legitimate users by accessing their session tokens.

5

Is CVE-2025-4614 remotely exploitable?

CVE-2025-4614 requires authenticated access, meaning it is not remotely exploitable without valid credentials.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203