CVE detail
CVE-2025-4614
An information disclosure vulnerability in Palo Alto Networks PAN-OS® software enables an authenticated administrator to view session tokens of users authenticated to the firewall web UI. This may allow impersonation of users whose session tokens are leaked. The security risk posed by this issue is significantly minimized when CLI access is restricted to a limited group of administrators. Cloud NGFW and Prisma® Access are not affected by this vulnerability.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 6.9 · diversity 5.0 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
1 source links · newest first
- https://security.paloaltonetworks.com/CVE-2025-4614security.paloaltonetworks.com
No excerpt available.
Exploitsecurity.paloaltonetworks.comOct 9, 2025, 7:15 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2024-8687CVSS 6.9 · Medium
An information exposure vulnerability exists in Palo Alto Networks PAN-OS software that enables a GlobalProtect end user to learn both the configured GlobalProtect uninstall passw…
- CVE-2023-0005CVSS 4.1 · Medium
A vulnerability in Palo Alto Networks PAN-OS software enables an authenticated administrator to expose the plaintext values of secrets stored in the device configuration and encry…
- CVE-2026-32468CVSS 7.5 · High
Unauthenticated Sensitive Data Exposure in Duitku Payment Gateway <= 2.11.14 versions.
- CVE-2024-58375CVSS 8.7 · High
OpenTofu versions 1.8.0 through 1.8.2 do not properly restrict sensitive variables and locals when users have opted into static evaluation of module sources, versions, and backend…
- CVE-2026-66462CVSS 7.5 · High
Unauthenticated Sensitive Data Exposure in WooCommerce Appointments <= 5.3.8 versions.
- CVE-2026-66444CVSS 6.5 · Medium
Subscriber Sensitive Data Exposure in Payment Forms for Paystack <= 4.0.5 versions.