CVE-2025-0136

Using the AES-128-CCM algorithm for IPSec on certain Palo Alto Networks PAN-OS® firewalls (PA-7500, PA-5400, PA-5400f, PA-3400, PA-1600, PA-1400, and PA-400 Series) leads to unencrypted data transfer to devices that are connected to the PAN-OS firewall through IPSec. This issue does not affect Cloud NGFWs, Prisma® Access instances, or PAN-OS VM-Series firewalls. NOTE: The AES-128-CCM encryption algorithm is not recommended for use.
CVSS

No CVSS.

Configurations

No configuration.

History

16 May 2025, 14:43

Type Values Removed Values Added
New CVE

Information

Published : 2025-05-14 19:15

Updated : 2025-05-16 14:43


NVD link : CVE-2025-0136

Mitre link : CVE-2025-0136

CVE.ORG link : CVE-2025-0136


JSON object : View

Products Affected

No product.

CWE
CWE-319

Cleartext Transmission of Sensitive Information