CVE-2025-4615: PAN-OS: Improper Neutralization of Input in the Management Web Interface (Severity: INFORMATIONAL)
An improper input neutralization vulnerability in the management web interface of the Palo Alto Networks PAN-OS® software enables an authenticated administrator to bypass system restrictions and execute arbitrary commands.
The security risk posed by this issue is significantly minimized when CLI access is restricted to a limited group of administrators.
Cloud NGFW and Prisma® Access are not affected by this vulnerability.
Affected Software
Remediation
Mitigation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-4615?
CVE-2025-4615 is classified as a high severity vulnerability due to its potential for abuse by authenticated administrators.
How do I fix CVE-2025-4615?
To resolve CVE-2025-4615, it is recommended to upgrade to the latest patched version of PAN-OS, Cloud NGFW, or Prisma Access as advised by Palo Alto Networks.
What does CVE-2025-4615 allow an attacker to do?
CVE-2025-4615 allows an authenticated administrator to bypass system restrictions and execute arbitrary commands via the management web interface.
Which Palo Alto Networks products are affected by CVE-2025-4615?
CVE-2025-4615 affects Palo Alto Networks PAN-OS, Cloud NGFW, and Prisma Access.
Is CVE-2025-4615 being actively exploited?
As of now, there is no public information confirming active exploitation of CVE-2025-4615, but its high severity indicates potential risk.