CVE-2025-4230 is a command injection vulnerability in Palo Alto Networks PAN-OS software, allowing an authenticated administrator with CLI access to execute arbitrary commands as a root user. This high-severity vulnerability (CVSS 8.4) requires high privileges and local access, but successful exploitation grants full control over the affected system. While Cloud NGFW and Prisma Access are not impacted, the risk is significantly reduced by restricting CLI access. There is currently no public exploit code available, and it is not known to be actively exploited, though it has garnered some community and media attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Palo Alto Networks | PAN-OS | >= 10.1.0, < 10.1.14-h15, >= 10.2.0, < 10.2.14, >= 11.1.0, < 11.1.10, >= 11.2.0, < 11.2.6CNA affecteddefault unaffected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:U/V:D/RE:X/U:Amber
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.