PT-2025-41451 · Palo Alto Networks · Pan-Os

·

CVE-2025-4614

·

Published

2025-10-08

·

Updated

2025-10-22

CVSS v4.0

4.8

Medium

VectorAV:N/AC:L/AT:N/PR:H/UI:P/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N/AU:N/R:U/V:C/RE:M/U:Amber
Name of the Vulnerable Software and Affected Versions Palo Alto Networks PAN-OS (affected versions not specified)
Description An information disclosure issue in the software allows an authenticated administrator to view session tokens of users authenticated to the firewall web UI. This could lead to the impersonation of users whose session tokens are leaked. The risk is reduced if CLI access is restricted to a limited group of administrators.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-05011
CVE-2025-4614

Affected Products

Pan-Os