CVE-2025-4619
Last modified
CVE-2025-4619 is a medium-severity vulnerability rated 6.6/10 on the CVSS scale. A denial-of-service (DoS) vulnerability in Palo Alto Networks PAN-OS software enables an unauthenticated attacker to reboot a firewall by sending a specially crafted packet through the dataplane. Repeated attempts to initiate a reboot causes the firewall to enter maintenance mode. This issue is applicable to the PAN-OS software versions listed below on PA-Series firewalls, VM-Series firewalls, and Prisma® Access software. EPSS estimates a 0.52% chance of exploitation in the next 30 days.
Description
A denial-of-service (DoS) vulnerability in Palo Alto Networks PAN-OS software enables an unauthenticated attacker to reboot a firewall by sending a specially crafted packet through the dataplane. Repeated attempts to initiate a reboot causes the firewall to enter maintenance mode. This issue is applicable to the PAN-OS software versions listed below on PA-Series firewalls, VM-Series firewalls, and Prisma® Access software. This issue does not affect Cloud NGFW. We have successfully completed the Prisma Access upgrade for all customers, with the exception of those facing issues such as conflicting maintenance windows. Remaining customers will be promptly scheduled for an upgrade through our standard upgrade process.
Metrics
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:U/V:C/RE:M/U:Amber
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2025-4619?
How severe is CVE-2025-4619?
How do I fix CVE-2025-4619?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-46179A SQL Injection vulnerability was discovered in the askquery…9.8
- CVE-2025-4618A sensitive information disclosure vulnerability in Palo Alt…4.4
- CVE-2025-46183The Utils.deserialize function in pgCodeKeeper 10.12.0 proce…8.2
- CVE-2025-46185An Insecure Permission vulnerability in pgcodekeeper 10.12.0…6.2
- CVE-2025-46188SourceCodester Client Database Management System 1.0 is vuln…9.8
- CVE-2025-46189SourceCodester Client Database Management System 1.0 is vuln…9.8
- CVE-2025-46190SourceCodester Client Database Management System 1.0 is vuln…9.8
- CVE-2025-46191Arbitrary File Upload in user_payment_update.php in SourceCo…9.8
- CVE-2025-46192SourceCodester Client Database Management System 1.0 is vuln…9.8
- CVE-2025-46193SourceCodester Client Database Management System 1.0 is vuln…9.8
- CVE-2025-46198Cross Site Scripting vulnerability in grav v.1.7.48, v.1.7.4…8.8
- CVE-2025-46199Cross Site Scripting vulnerability in grav v.1.7.48 and befo…9.8
Are you affected by CVE-2025-4619?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
