Back to vendor advisories
Palo Alto Networks Security AdvisoriesCVE-2025-4619

CVE-2025-4619: PAN-OS: Firewall Denial of Service (DoS) Using Specially Crafted Packets

A denial-of-service (DoS) vulnerability in Palo Alto Networks PAN-OS software enables an unauthenticated attacker to reboot a firewall by sending a specially crafted packet through the dataplane. Repeated attempts to initiate a reboot causes the firewall to enter maintenance mode. This issue is applicable to the PAN-OS software versions listed below on PA-Series firewalls, VM-Series firewalls, and Prisma® Access software. This issue does not affect Cloud NGFW. We have successfully completed the Prisma Access upgrade for all customers, with the exception of those facing issues such as conflicting maintenance windows. Remaining customers will be promptly scheduled for an upgrade through our standard upgrade process.

8.7CVSS out of 10High severity
Scope

What the vendor says is affected

  • Cloud NGFW
  • PAN-OS
  • Prisma Access
  • PAN-OS 12.1
  • PAN-OS 11.2
  • PAN-OS 11.1
  • PAN-OS 10.2
  • PAN-OS 10.1

Versions the vendor lists as fixed

  • Cloud NGFW All
  • PAN-OS 12.1 All
  • PAN-OS 11.2 >= 11.2.2-h2, >= 11.2.3-h6, >= 11.2.4-h4, >= 11.2.5
  • PAN-OS 11.1 < 11.1.2-h9, >= 11.1.2-h18, < 11.1.3-h2, < 11.1.4-h4, >= 11.1.4-h13, >= 11.1.6-h1, >= 11.1.7
  • PAN-OS 10.2 < 10.2.4-h25, < 10.2.7-h11, >= 10.2.7-h24, < 10.2.8-h10, >= 10.2.8-h21, < 10.2.9-h6, >= 10.2.9-h21, < 10.2.10-h2, >= 10.2.10-h14, >= 10.2.11-h12, >= 10.2.12-h6,
  • PAN-OS 10.1 All
  • Prisma Access < 10.2.4-h25 on PAN-OS, >= 10.2.10-h14 on PAN-OS, >= 11.2.4-h4 on PAN-OS
Next step

What the vendor recommends

VERSION MINOR VERSION SUGGESTED SOLUTION Cloud NGFW No action needed. PAN-OS 12.1 No action needed. PAN-OS 11.2 11.2.0 through 11.2.4 Upgrade to 11.2.4-h4 or 11.2.5 or later. 11.2.0 through 11.2.3 Upgrade to 11.2.3-h6 or 11.2.5 or later. 11.2.0 through 11.2.2 Upgrade to 11.2.2-h2 or 11.2.5 or later. PAN-OS 11.1 11.1.0 through 11.1.6 Upgrade to 11.1.6-h1 or 11.1.7 or later. 11.1.0 through 11.1.4 Upgrade to 11.1.4-h13 or 11.1.7 or later. 11.1.0 through 11.1.3 Remain on a version older than 11.1.3-h2 or upgrade to 11.1.4-h13 or 11.1.7 or later. 11.1.0 through 11.1.2 Upgrade to 11.1.2-h18 or 11.1.7 or later. PAN-OS 10.2 10.2.0 through 10.2.13 Upgrade to 10.2.13-h3 or 10.2.14 or later. 10.2.0 through 10.2.12 Upgrade to 10.2.12-h6 or 10.2.14 or later. 10.2.0 through 10.2.11 Upgrade to 10.2.11-h12 or 10.2.14 or later. 10.2.0 through 10.2.10 Upgrade to 10.2.10-h14 or 10.2.14 or later. 10.2.0 through 10.2.9 Upgrade to 10.2.9-h21 or 10.2.14 or later. 10.2.0 through 10.2.8 Upgrade to 10.2.8-h21 or 10.2.14 or later. 10.2.0 through 10.2.7 Upgrade to 10.2.7-h24 or 10.2.14 or later. 10.2.0 through 10.2.4 Remain on a version older than 10.2.4-h25 PAN-OS 10.1 No action needed. All older Upgrade to a supported fixed version. unsupported PAN-OS versions Prisma Access on PAN-OS 11.2.0 through 11.2.4 Upgrade to 11.2.4-h4 or later 10.2.0 through 10.2.10 Upgrade to 10.2.10-h14 or 11.2.4-h4 or later. 10.2.0 through 10.2.4 Remain on a version older than 10.2.4-h25.

Review the complete instructions on the vendor's site
Timeline

When this advisory changed

  1. Published by Palo Alto Networks

    The publication date reported by the vendor.

  2. Added to SecurityAlert

    We collected the advisory from the official source.

  3. Confirmed at the source

    Our collector saw this advisory during a later source check.

Vulnerabilities

CVEs named in this advisory