| 1.1 | CVE-2025-4614
PAN-OS: Session Token Disclosure Vulnerability | Cloud NGFW PAN-OS 12.1 PAN-OS 11.2 PAN-OS 11.1 PAN-OS 10.2 Prisma Access | None None < 11.2.8 < 11.1.6-h21 < 10.2.17 None | All All >= 11.2.8 >= 11.1.6-h21 >= 10.2.17 All | 2025-10-08 | 2025-10-08 |
| 4.5 | CVE-2025-4615
PAN-OS: Improper Neutralization of Input in the Management Web Interface | Cloud NGFW PAN-OS 12.1 PAN-OS 11.2 PAN-OS 11.1 PAN-OS 10.2 Prisma Access | None None < 11.2.8 < 11.1.6-h21, < 11.1.10-h7 < 10.2.17 None | All All >= 11.2.8 >= 11.1.6-h21, >= 11.1.10-h7 >= 10.2.17 All | 2025-10-08 | 2025-11-11 |
| 3.3 | CVE-2025-2182
PAN-OS: Firewall Clusters using the MACsec Protocol Expose the Connectivity Association Key (CAK) | Cloud NGFW PAN-OS PAN-OS 11.2 PAN-OS 11.1 PAN-OS 10.2 PAN-OS 10.1 Prisma Access | None None on devices other than PA-7500 < 11.2.8 on PA-7500 < 11.1.10 on PA-7500 None on PA-7500 None on PA-7500 None | All All on devices other than PA-7500 >= 11.2.8 on PA-7500 >= 11.1.10 on PA-7500 All on PA-7500 All on PA-7500 All | 2025-08-13 | 2025-08-13 |
| 5.7 | CVE-2025-4230
PAN-OS: Authenticated Admin Command Injection Vulnerability Through CLI | Cloud NGFW PAN-OS 11.2 PAN-OS 11.1 PAN-OS 10.2 PAN-OS 10.1 Prisma Access | None < 11.2.6 < 11.1.6-h14, < 11.1.10 < 10.2.10-h27 < 10.1.14-h15 None | All >= 11.2.6 >= 11.1.6-h14, >= 11.1.10 >= 10.2.10-h27 >= 10.1.14-h15 All | 2025-06-11 | 2025-06-30 |
| 4.6 | CVE-2025-0130
PAN-OS: Firewall Denial-of-Service (DoS) in the Web-Proxy Feature via a Burst of Maliciously Crafted Packets | Cloud NGFW PAN-OS 11.2 PAN-OS 11.1 PAN-OS 10.2 PAN-OS 10.1 Prisma Access | None < 11.2.5 < 11.1.6-h1, < 11.1.7-h2, < 11.1.8 None None None | All >= 11.2.5 >= 11.1.6-h1, >= 11.1.7-h2, >= 11.1.8 All All All | 2025-05-14 | 2025-05-14 |