An information disclosure vulnerability in the SD-WAN feature of Palo Alto Networks PAN-OS® software enables an unauthorized user to view unencrypted data sent from the firewall through the SD-WAN interface. This requires the user to be able to intercept packets sent from the firewall.
Cloud NGFW and Prisma® Access are not affected by this vulnerability.
                
            CVSS
                No CVSS.
References
                    | Link | Resource | 
|---|---|
| https://security.paloaltonetworks.com/CVE-2025-4229 | 
Configurations
                    No configuration.
History
                    16 Jun 2025, 12:32
| Type | Values Removed | Values Added | 
|---|---|---|
| Summary | 
 | 
13 Jun 2025, 06:15
| Type | Values Removed | Values Added | 
|---|---|---|
| New CVE | 
Information
                Published : 2025-06-13 06:15
Updated : 2025-06-16 12:32
NVD link : CVE-2025-4229
Mitre link : CVE-2025-4229
CVE.ORG link : CVE-2025-4229
JSON object : View
Products Affected
                No product.
CWE
                
                    
                        
                        CWE-497
                        
            Exposure of Sensitive System Information to an Unauthorized Control Sphere
