{ "dataType": "CVE_RECORD", "dataVersion": "5.1", "cveMetadata": { "cveId": "CVE-2025-2182", "assignerOrgId": "d6c1279f-00f6-4ef7-9217-f89ffe703ec0", "state": "PUBLISHED", "assignerShortName": "palo_alto", "dateReserved": "2025-03-10T17:56:24.875Z", "datePublished": "2025-08-13T17:03:21.617Z", "dateUpdated": "2025-08-13T20:32:15.474Z" }, "containers": { "cna": { "affected": [ { "defaultStatus": "unaffected", "product": "Cloud NGFW", "vendor": "Palo Alto Networks", "versions": [ { "changes": [ { "at": "3.2.449", "status": "unaffected" } ], "lessThan": "3.2.449", "status": "unaffected", "version": "All", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:o:palo_alto_networks:pan-os:11.2.7:*:*:*:*:*:PA-7500:*", "cpe:2.3:o:palo_alto_networks:pan-os:11.2.6:*:*:*:*:*:PA-7500:*", "cpe:2.3:o:palo_alto_networks:pan-os:11.2.5:*:*:*:*:*:PA-7500:*", "cpe:2.3:o:palo_alto_networks:pan-os:11.2.4:*:*:*:*:*:PA-7500:*", "cpe:2.3:o:palo_alto_networks:pan-os:11.2.3:*:*:*:*:*:PA-7500:*", "cpe:2.3:o:palo_alto_networks:pan-os:11.2.2:*:*:*:*:*:PA-7500:*", "cpe:2.3:o:palo_alto_networks:pan-os:11.2.1:*:*:*:*:*:PA-7500:*", "cpe:2.3:o:palo_alto_networks:pan-os:11.2.0:*:*:*:*:*:PA-7500:*", "cpe:2.3:o:palo_alto_networks:pan-os:11.1.9:*:*:*:*:*:PA-7500:*", "cpe:2.3:o:palo_alto_networks:pan-os:11.1.8:*:*:*:*:*:PA-7500:*", "cpe:2.3:o:palo_alto_networks:pan-os:11.1.6:*:*:*:*:*:PA-7500:*", "cpe:2.3:o:palo_alto_networks:pan-os:11.1.5:*:*:*:*:*:PA-7500:*", "cpe:2.3:o:palo_alto_networks:pan-os:11.1.4:*:*:*:*:*:PA-7500:*", "cpe:2.3:o:palo_alto_networks:pan-os:11.1.3:*:*:*:*:*:PA-7500:*", "cpe:2.3:o:palo_alto_networks:pan-os:11.1.2:*:*:*:*:*:PA-7500:*", "cpe:2.3:o:palo_alto_networks:pan-os:11.1.1:*:*:*:*:*:PA-7500:*", "cpe:2.3:o:palo_alto_networks:pan-os:11.1.0:*:*:*:*:*:PA-7500:*" ], "defaultStatus": "unaffected", "modules": [ "Clusters" ], "platforms": [ "PA-7500" ], "product": "PAN-OS", "vendor": "Palo Alto Networks", "versions": [ { "changes": [ { "at": "11.2.8", "status": "unaffected" } ], "lessThan": "11.2.8", "status": "affected", "version": "11.2.0", "versionType": "custom" }, { "changes": [ { "at": "11.1.10", "status": "unaffected" } ], "lessThan": "11.1.10", "status": "affected", "version": "11.1.0", "versionType": "custom" }, { "status": "unaffected", "version": "10.2.0", "versionType": "custom" }, { "status": "unaffected", "version": "10.1.0", "versionType": "custom" } ] }, { "defaultStatus": "unaffected", "platforms": [ "devices other than PA-7500" ], "product": "PAN-OS", "vendor": "Palo Alto Networks", "versions": [ { "status": "unaffected", "version": "All", "versionType": "custom" } ] }, { "defaultStatus": "unaffected", "product": "Prisma Access", "vendor": "Palo Alto Networks", "versions": [ { "status": "unaffected", "version": "All", "versionType": "custom" } ] } ], "configurations": [ { "lang": "eng", "supportingMedia": [ { "base64": false, "type": "text/html", "value": "
The following conditions must be true to be vulnerable to this issue:
Your PA-7500 Series devices must be in an NGFW cluster. For more information regarding NGFW Clusters see our documentation.
A MACsec policy must be configured and enabled for the NGFW cluster. For more information about MACsec profiles please see our documentation.
| Version | Minor Version | Suggested Solution |
|---|---|---|
| Cloud NGFW | No action needed. | |
| PAN-OS 11.2 on PA-7500 | \n 11.2.0 through 11.2.7 | \nUpgrade to 11.2.8 or later. | \n
| PAN-OS 11.1 on PA-7500 | \n 11.1.0 through 11.1.9 | \nUpgrade to 11.1.10 or later. | \n
| PAN-OS 10.2 on PA-7500 | No action needed. | |
| PAN-OS 10.1 on PA-7500 | No action needed. | |
| PAN-OS on devices other than PA-7500 | No action needed. | |
| All older unsupported PAN-OS versions | Upgrade to a supported fixed version. | |
| Prisma Access | No action needed. |