CVE-2025-4229Exposure of Sensitive System Information to an Unauthorized Control Sphere in Palo Alto Networks Pan-os

Severity
6.0MEDIUMNVD
EPSS
0.4%
top 40.22%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 13

Description

An information disclosure vulnerability in the SD-WAN feature of Palo Alto Networks PAN-OS® software enables an unauthorized user to view unencrypted data sent from the firewall through the SD-WAN interface. This requires the user to be able to intercept packets sent from the firewall. Cloud NGFW and Prisma® Access are not affected by this vulnerability.

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N

Affected Packages4 packages

CVEListV5palo_alto_networks/pan-os11.2.011.2.7+3
Palo Altopaloalto/pan-os

🔴Vulnerability Details

2
CVEList
PAN-OS: Traffic Information Disclosure Vulnerability2025-06-13
GHSA
GHSA-6358-8vph-jx32: An information disclosure vulnerability in the SD-WAN feature of Palo Alto Networks PAN-OS® software enables an unauthorized user to view unencrypted2025-06-13

📋Vendor Advisories

1
Palo Alto
PAN-OS: Traffic Information Disclosure Vulnerability
CVE-2025-4229 — Palo Alto Networks Pan-os vulnerability | cvebase