Security Advisory

CVE-2025-4615

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2025-10-09 18:28:04
Last updated 2026-04-01 00:44:17
Assigner palo_alto
CVSS score 5.4
State PUBLISHED

Description

An improper input neutralization vulnerability in the management web interface of the Palo Alto Networks PAN-OS® software enables an authenticated administrator to bypass system restrictions and execute arbitrary commands. The security risk posed by this issue is significantly minimized when CLI access is restricted to a limited group of administrators. Cloud NGFW and Prisma® Access are not affected by this vulnerability.