216.73.216.226

CVE-2025-4615

· Published 09/10/2025 19:15 · Modified 09/10/2025 19:15

Labels: CVE-2025-4615 2025-10-09CVE-2025-4615CWE-83[email protected]

Essential information

Published
09/10/2025 19:15
Modified
09/10/2025 19:15
Author
Creator
CVSS
7.0 HIGH (v3) 7.0 HIGH (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

An improper input neutralization vulnerability in the management web interface of the Palo Alto Networks PAN-OS® software enables an authenticated administrator to bypass system restrictions and execute arbitrary commands. The security risk posed by this issue is significantly minimized when CLI access is restricted to a limited group of administrators. Cloud NGFW and Prisma® Access are not affected by this vulnerability.

NVD status

Status
Received — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
paloaltonetworks / pan-os cpe:2.3:a:paloaltonetworks:pan-os:*:*:*:*:*:*:*:*

References