CVE-2025-4229: Palo Alto Networks Cloud Ngfw

Medium severity, CVSS 6.0. EPSS: 0.5% chance of exploitation in the next 30 days.

An information disclosure vulnerability in the SD-WAN feature of Palo Alto Networks PAN-OS® software enables an unauthorized user to view unencrypted data sent from the firewall through the SD-WAN interface. This requires the user to be able to intercept packets sent from the firewall. Cloud NGFW and Prisma® Access are not affected by this vulnerability.

Affected products

  • Palo Alto Networks Cloud Ngfw
  • Palo Alto Networks PAN-OS: from 11.2.0, before 11.2.7 (fixed in 11.2.7); from 11.1.0, before 11.1.10 (fixed in 11.1.10); from 10.2.0, before 10.2.17 (fixed in 10.2.17); from 10.1.0, before 10.1.14-h16 (fixed in 10.1.14-h16)
  • Palo Alto Networks Prisma Access

Published 2025-06-13. Last modified 2026-06-17.