CVE-2025-0129

CRITICAL

Palo Alto Networks Prisma Access Browser - Privilege Escalation

Title source: llm
STIX 2.1

Description

An improper exception check in Palo Alto Networks Prisma Access Browser allows a low privileged user to prevent Prisma Access Browser from applying it's Policy Rules. This enables the user to use Prisma Access Browser without any restrictions.

Scores

CVSS v4 9.3
EPSS 0.0028
EPSS Percentile 51.5%
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N/AU:N/R:U/V:D/RE:L/U:Amber

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-306 CWE-754
Status published
Products (1)
Palo Alto Networks/Prisma Access Browser 1 - 132.83.3017.1
Published Apr 11, 2025
Tracked Since Feb 18, 2026