An improper input neutralization vulnerability in the management web interface of the Palo Alto Networks PAN-OS® software enables an authenticated administrator to bypass system restrictions and execute arbitrary commands.
The security risk posed by this issue is significantly minimized when CLI access is restricted to a limited group of administrators.
Cloud NGFW and Prisma® Access are not affected by this vulnerability.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://security.paloaltonetworks.com/CVEN-2025-4615 |
![]() ![]() |
History
Fri, 10 Oct 2025 11:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Paloaltonetworks
Paloaltonetworks cloud Ngfw Paloaltonetworks pan-os Paloaltonetworks prisma Access |
|
Vendors & Products |
Paloaltonetworks
Paloaltonetworks cloud Ngfw Paloaltonetworks pan-os Paloaltonetworks prisma Access |
Thu, 09 Oct 2025 19:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Thu, 09 Oct 2025 18:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | An improper input neutralization vulnerability in the management web interface of the Palo Alto Networks PAN-OS® software enables an authenticated administrator to bypass system restrictions and execute arbitrary commands. The security risk posed by this issue is significantly minimized when CLI access is restricted to a limited group of administrators. Cloud NGFW and Prisma® Access are not affected by this vulnerability. | |
Title | PAN-OS: Improper Neutralization of Input in the Management Web Interface | |
Weaknesses | CWE-83 | |
References |
| |
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: palo_alto
Published: 2025-10-09T18:28:04.905Z
Updated: 2025-10-09T19:08:50.531Z
Reserved: 2025-05-12T22:05:13.606Z
Link: CVE-2025-4615

Updated: 2025-10-09T19:08:46.934Z

Status : Received
Published: 2025-10-09T19:15:43.490
Modified: 2025-10-09T19:15:43.490
Link: CVE-2025-4615

No data.