CVE-2025-4619 Details
Description
A denial-of-service (DoS) vulnerability in Palo Alto Networks PAN-OS software enables an unauthenticated attacker to reboot a firewall by sending a specially crafted packet through the dataplane. Repeated attempts to initiate a reboot causes the firewall to enter maintenance mode. This issue is applicable to the PAN-OS software versions listed below on PA-Series firewalls, VM-Series firewalls, and Prisma® Access software. This issue does not affect Cloud NGFW. We have successfully completed the Prisma Access upgrade for all customers, with the exception of those facing issues such as conflicting maintenance windows. Remaining customers will be promptly scheduled for an upgrade through our standard upgrade process.
A denial-of-service vulnerability has been identified in Palo Alto Networks PAN-OS software. This vulnerability allows an unauthenticated attacker to reboot a firewall by sending a specially crafted packet through the dataplane. When the reboot is initiated repeatedly, the firewall enters maintenance mode. This issue affects PA-Series firewalls, VM-Series firewalls, and Prisma Access software, but does not impact Cloud NGFW. The vulnerability is present in PAN-OS versions 10.2, 11.1, and 11.2, with specific subversion ranges applicable.
Users can upgrade to PAN-OS 11.2.4-h4 or 11.2.5, or to PAN-OS 10.2.13-h3 or 10.2.14. For Prisma Access, upgrade to 11.2.4-h4 or 10.2.10-h14. Users on older, unsupported PAN-OS versions should upgrade to a supported fixed version.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Nov 13, 2025CISA-ADP
Assessed Nov 14, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://security.paloaltonetworks.com/CVE-2025-4619 | [email protected] | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-754 | Improper Check for Unusual or Exceptional Conditions | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Palo Alto Networks PAN-OS | >= 11.2.0, < 11.2.5 (semver) >= 11.2.4, < 11.2.4-h4 (semver) >= 11.2.3, < 11.2.3-h6 (semver) >= 11.2.2, < 11.2.2-h2 (semver) >= 11.1.0, < 11.1.7 (semver) >= 11.1.6, < 11.1.6-h1 (semver) >= 11.1.4, < 11.1.4-h13 (semver) >= 11.1.4, < 11.1.4-h4 (semver) >= 11.1.3, < 11.1.3-h2 (semver) >= 11.1.2, < 11.1.2-h18 (semver) >= 11.1.2, < 11.1.2-h9 (semver) >= 10.2.0, < 10.2.14 (semver) >= 10.2.13, < 10.2.13-h3 (semver) >= 10.2.12, < 10.2.12-h6 (semver) >= 10.2.11, < 10.2.11-h12 (semver) >= 10.2.10, < 10.2.10-h14 (semver) >= 10.2.10, < 10.2.10-h2 (semver) >= 10.2.9, < 10.2.9-h21 (semver) >= 10.2.9, < 10.2.9-h6 (semver) >= 10.2.8, < 10.2.8-h21 (semver) >= 10.2.8, < 10.2.8-h10 (semver) >= 10.2.7, < 10.2.7-h24 (semver) >= 10.2.7, < 10.2.7-h11 (semver) |
CPE
Remediation
| |
| Palo Alto Networks PA-Series | All versions |
CPE
Remediation
| |
| Palo Alto Networks VM-Series | All versions |
CPE
Remediation
| |
| Palo Alto Networks Prisma Access | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Nov 13, 2025 | New CVE Received | [email protected] |
Volerion