NA
CVSSv3

CVE-2025-0136

CVSSv4: 5.3 | CVSSv3: NA | CVSSv2: NA | VMScore: 630 | EPSS: 0.00013 | KEV: Not Included
Published: 14/05/2025 Updated: 16/05/2025

Vulnerability Summary

Unencrypted IPSec Data Transfer Vulnerability in Palo Alto Networks PAN-OS Firewalls

A vulnerability exists in Palo Alto Networks PAN-OS® firewalls (PA-7500, PA-5400, PA-5400f, PA-3400, PA-1600, PA-1400, and PA-400 Series) when using the AES-128-CCM algorithm for IPSec. This issue causes unencrypted data transfer to devices connected through IPSec on these specific firewall models. The problem does not impact Cloud NGFWs, Prisma® Access instances, or PAN-OS VM-Series firewalls. The AES-128-CCM encryption algorithm is explicitly not recommended for use due to its potential security risks.

Solution

Version
Minor Version
Suggested Solution
PAN-OS 11.2

No action needed
PAN-OS 11.111.1.0 through 11.1.4
Upgrade to 11.1.5 or laterPAN-OS 11.0
11.0.0 through 11.0.6
Upgrade to 11.0.7 or later
PAN-OS 10.2
10.2.0 through 10.2.10Upgrade to 10.2.11 or laterPAN-OS 10.1
10.1.0 through 10.1.14
Upgrade to 10.1.14-h14 or later
All other older
unsupported
PAN-OS versions Upgrade to a supported fixed version.
PAN-OS 11.0 is EoL. We listed it in this section for completeness and because we added a patch for PAN-OS 11.0 before it reached EoL. If you are running PAN-OS 11.0 on any of your firewalls, though, we strongly recommend that you upgrade to a supported (non-EoL) fixed version.
Vulnerable Product Search on Vulmon Subscribe to Product

paloaltonetworks pan-os 11.1.4

paloaltonetworks pan-os 11.1.3

paloaltonetworks pan-os 11.1.2

paloaltonetworks pan-os 11.1.1

paloaltonetworks pan-os 11.1.0

paloaltonetworks pan-os 11.0.6

paloaltonetworks pan-os 11.0.5

paloaltonetworks pan-os 11.0.4

paloaltonetworks pan-os 11.0.3

paloaltonetworks pan-os 11.0.2

paloaltonetworks pan-os 11.0.1

paloaltonetworks pan-os 11.0.0

paloaltonetworks pan-os 10.2.10

paloaltonetworks pan-os 10.2.9

paloaltonetworks pan-os 10.2.8

paloaltonetworks pan-os 10.2.7

paloaltonetworks pan-os 10.2.6

paloaltonetworks pan-os 10.2.5

paloaltonetworks pan-os 10.2.4

paloaltonetworks pan-os 10.2.3

paloaltonetworks pan-os 10.2.2

paloaltonetworks pan-os 10.2.1

paloaltonetworks pan-os 10.2.0

paloaltonetworks pan-os 10.1.14

paloaltonetworks pan-os 10.1.13

paloaltonetworks pan-os 10.1.12

paloaltonetworks pan-os 10.1.11

paloaltonetworks pan-os 10.1.10

paloaltonetworks pan-os 10.1.9

paloaltonetworks pan-os 10.1.8

paloaltonetworks pan-os 10.1.7

paloaltonetworks pan-os 10.1.6

paloaltonetworks pan-os 10.1.5

paloaltonetworks pan-os 10.1.4

paloaltonetworks pan-os 10.1.3

paloaltonetworks pan-os 10.1.2

paloaltonetworks pan-os 10.1.1

paloaltonetworks pan-os 10.1.0

palo alto networks cloud ngfw

palo alto networks pan-os

palo alto networks prisma access