PT-2025-41451 · Palo Alto Networks · Pan-Os

Visa Inc

·

Published

2025-10-08

·

Updated

2025-10-22

·

CVE-2025-4614

CVSS v4.0

4.8

Medium

VectorAV:N/AC:L/AT:N/PR:H/UI:P/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N/AU:N/R:U/V:C/RE:M/U:Amber
Name of the Vulnerable Software and Affected Versions Palo Alto Networks PAN-OS (affected versions not specified)
Description An information disclosure issue in the software allows an authenticated administrator to view session tokens of users authenticated to the firewall web UI. This could lead to the impersonation of users whose session tokens are leaked. The risk is reduced if CLI access is restricted to a limited group of administrators.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Weakness Enumeration

Related Identifiers

BDU:2026-05011
CVE-2025-4614

Affected Products

Pan-Os