Palo Alto Networks PAN-OS 10.1.x < 10.1.14-h13 / 10.2.x < 10.2.15 / 11.1.x < 11.1.8 / 11.2.x < 11.2.6 Vulnerability

medium Nessus Plugin ID 234099

Synopsis

The remote PAN-OS host is affected by a vulnerability

Description

The version of Palo Alto Networks PAN-OS running on the remote host is 10.1.x prior to 10.1.14-h13 or 10.2.x prior to 10.2.15 or 11.1.x prior to 11.1.8 or 11.2.x prior to 11.2.6. It is, therefore, affected by a vulnerability.

A vulnerability in the Palo Alto Networks PAN-OS software enables unlicensed administrators to view clear-text data captured using the packet capture feature (https://docs.paloaltonetworks.com/pan- os/11-0/pan-os-admin/monitoring/take-packet-captures/take-a-custom-packet-capture) in decrypted HTTP/2 data streams traversing network interfaces on the firewall. HTTP/1.1 data streams are not impacted.

In normal conditions, decrypted packet captures are available to firewall administrators after they obtain and install a free Decryption Port Mirror license. The license requirement ensures that this feature can only be used after approved personnel purposefully activate the license. For more information, review how to configure decryption port mirroring (https://docs.paloaltonetworks.com/network- security/decryption/administration/monitoring-decryption/configure-decryption-port-mirroring).

The administrator must obtain network access to the management interface (web, SSH, console, or telnet) and successfully authenticate to exploit this issue. Risk of this issue can be greatly reduced by restricting access to the management interface to only trusted administrators and from only internal IP addresses according to our recommended critical deployment guidelines (https://live.paloaltonetworks.com/t5/community-blogs/tips-amp-tricks-how-to-secure-the-management-access- of-your-palo/ba-p/464431).

Customer firewall administrators do not have access to the packet capture feature in Cloud NGFW. This feature is available only to authorized Palo Alto Networks personnel permitted to perform troubleshooting.

Prisma Access is not impacted by this vulnerability.


Tenable has extracted the preceding description block directly from the PAN-OS security advisory.

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.

Solution

Upgrade to PAN-OS 10.1.14-h13 / 10.2.15 / 11.1.8 / 11.2.6 or later

See Also

https://security.paloaltonetworks.com/CVE-2025-0123

Plugin Details

Severity: Medium

ID: 234099

File Name: palo_alto_CVE-2025-0123.nasl

Version: 1.1

Type: combined

Published: 4/9/2025

Updated: 4/9/2025

Configuration: Enable paranoid mode

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 6.1

CVSS v2

Risk Factor: Medium

Base Score: 4

Temporal Score: 3

Vector: CVSS2#AV:N/AC:L/Au:S/C:P/I:N/A:N

CVSS Score Source: CVE-2025-0123

CVSS v3

Risk Factor: Medium

Base Score: 4.4

Temporal Score: 3.9

Vector: CVSS:3.0/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

CVSS v4

Risk Factor: None

Threat Vector: CVSS:4.0/E:U

Vector: CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N

Vulnerability Information

CPE: cpe:/o:paloaltonetworks:pan-os

Required KB Items: Settings/ParanoidReport, Host/Palo_Alto/Firewall/Version, Host/Palo_Alto/Firewall/Full_Version, Host/Palo_Alto/Firewall/Source

Exploit Ease: No known exploits are available

Patch Publication Date: 4/9/2025

Vulnerability Publication Date: 4/9/2025

Reference Information

CVE: CVE-2025-0123

CWE: 312