PAN-OS: Firewall Clusters using the MACsec Protocol Expose the Connectivity Association Key (CAK)
Published Aug 13, 2025
5.6
MEDIUMCVSS 4.0
EPSS 0.12%
Description
A problem with the implementation of the MACsec protocol in Palo Alto Networks PAN-OS® results in the cleartext exposure of the connectivity association key (CAK). This issue is only applicable to PA-7500 Series devices which are in an NGFW cluster. A user who possesses this key can read messages being sent between devices in a NGFW Cluster. There is no impact in non-clustered firewalls or clusters of firewalls that do not enable MACsec.
Affected products
-
- Version 11.1.0StatusaffectedConstraints<11.1.10
- Version 11.2.0StatusaffectedConstraints<11.2.8
- Version 10.1.0StatusunaffectedConstraints-
- Version 10.2.0StatusunaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Palo Alto Networks | Pan-OS | unaffected |
|
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
Version Minor Version Suggested Solution Cloud NGFW No action needed. PAN-OS 11.2 on PA-7500
11.2.0 through 11.2.7 Upgrade to 11.2.8 or later.
PAN-OS 11.1 on PA-7500
11.1.0 through 11.1.9 Upgrade to 11.1.10 or later. PAN-OS 10.2 on PA-7500 No action needed.PAN-OS 10.1 on PA-7500 No action needed.PAN-OS on devices other than PA-7500 No action needed.All older unsupported PAN-OS versions Upgrade to a supported fixed version.Prisma Access No action needed.
References (1)
- https://security.paloaltonetworks.com/CVE-2025-2182 vendor-advisory
| Link | Providers | Tags |
|---|---|---|
| https://security.paloaltonetworks.com/CVE-2025-2182 | vendor-advisory |
Change history (0)
No recorded changes yet.