ZeroHour
Infosecurity Magazinepublished ()ingested Kevin Poireault

Palo Alto Networks Patches Series of Vulnerabilities

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2025-4230
A command injection vulnerability in Palo Alto Networks PAN-OS® software enables an authenticated administrator to bypass system restrictions and run arbitrary

A command injection vulnerability in Palo Alto Networks PAN-OS® software enables an authenticated administrator to bypass system restrictions and run arbitrary commands as a root user. To be able to exploit this issue, the user must have access to the PAN-OS CLI. The security risk posed by this issue is significantly minimized when CLI access is restricted to a limited group of administrators. Cloud NGFW and Prisma® Access are not affected by this vulnerability.

NVD description · AI analysis pending
8.4<1%
CVE-2025-4231
A command injection vulnerability in Palo Alto Networks PAN-OS® enables an authenticated administrative user to perform actions as the root user.

A command injection vulnerability in Palo Alto Networks PAN-OS® enables an authenticated administrative user to perform actions as the root user. The attacker must have network access to the management web interface and successfully authenticate to exploit this issue. Cloud NGFW and Prisma Access are not impacted by this vulnerability.

NVD description · AI analysis pending
8.6<1%
  • paloaltonetworks pan-os
CVE-2025-4232
An improper neutralization of wildcards vulnerability in the log collection feature of Palo Alto Networks GlobalProtect™ app on macOS allows a non administrativ

An improper neutralization of wildcards vulnerability in the log collection feature of Palo Alto Networks GlobalProtect™ app on macOS allows a non administrative user to escalate their privileges to root.

NVD description · AI analysis pending
8.5<1%
  • paloaltonetworks globalprotect
CVE-2025-4233
An insufficient implementation of cache vulnerability in Palo Alto Networks Prisma® Access Browser enables users to bypass certain data control policies.

An insufficient implementation of cache vulnerability in Palo Alto Networks Prisma® Access Browser enables users to bypass certain data control policies.

NVD description · AI analysis pending
5.1<1%
Full article227 words · extracted from infosecurity-magazine.com · click to collapse

Cybersecurity giant Palo Alto Networks issued a series of patches on June 11 for vulnerabilities across its range of products, including GlobalProtect App, Cortex XDR, PAN-OS, and the Prisma Access Browser.

Six flaws are in Palo Alto’s products, ranging from low – with CVSS scores of 0.3, 1 and 2.3 – to high severity.

The most critical vulnerability, tracked as CVE-2025-4232, is an authenticated code injection affecting GlobalProtect App versions 6.0 to 6.3 on macOS. It was attributed a high-severity CVSS score of 7.1 and should be patched with “moderate” urgency, according to Palo Alto.

Two other flaws, authenticated admin command injection vulnerabilities affecting PAN-OS versions 10.1 to 11.2, have been attributed a medium severity score (5.7 for CVE-2025-4230 and 6.1 for CVE-2025-4231).

Finally, Palo Alto also implemented a set of 11 fixes in the Google Chrome browser which affected the security vendor’s Prisma Access Browser. A further patch was issued for CVE-2025-4233, an inappropriate implementation in the cache, also affecting the Prisma Access Browser.

The set of 12 weaknesses was attributed a high-severity CVSS score of 8.6.

Chrome’s open-source version, Chromium, is the building block of Palo Alto’s Prisma Access Browser.

Palo Alto said it is not aware of any instances where these vulnerabilities have been exploited in attacks.

Photo credits: Tada Images/Michael Vi/Shutterstock

Read now: Hackers Chain Exploits of Three Palo Alto Networks Firewall Flaws

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.infosecurity-magazine.com/news/palo-alto-networks-patches-series/