CVE Database
/

CVE-2025-4229

Back to search

CVE-2025-4229

Published: Jun 13, 2025

Modified: Jun 13, 2025

PUBLISHED

Description

An information disclosure vulnerability in the SD-WAN feature of Palo Alto Networks PAN-OS® software enables an unauthorized user to view unencrypted data sent from the firewall through the SD-WAN interface. This requires the user to be able to intercept packets sent from the firewall. Cloud NGFW and Prisma® Access are not affected by this vulnerability.

VendorProductVersions

Palo Alto Networks

Cloud NGFW

unaffected
All

Palo Alto Networks

PAN-OS

affected
11.2.0 - < 11.2.7
affected
11.1.0 - < 11.1.10
affected
10.2.0 - < 10.2.17
affected
10.1.0 - < 10.1.14-h16

Palo Alto Networks

Prisma Access

unaffected
All

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now