CVE-2025-4615
09.10.2025, 19:15
An improper input neutralization vulnerability in the management web interface of the Palo Alto Networks PAN-OS software enables an authenticated administrator to bypass system restrictions and execute arbitrary commands. The security risk posed by this issue is significantly minimized when CLI access is restricted to a limited group of administrators. Cloud NGFW and Prisma Access are not affected by this vulnerability.Enginsight
| Vendor | Product | Version |
|---|---|---|
| paloaltonetworks | pan-os | 10.2.0 ≤ 𝑥 < 10.2.17 |
| paloaltonetworks | pan-os | 11.1.0 ≤ 𝑥 < 11.1.11 |
| paloaltonetworks | pan-os | 11.2.0 ≤ 𝑥 < 11.2.8 |
𝑥
= Vulnerable software versions