A problem with the implementation of the MACsec protocol in Palo Alto Networks PAN-OSĀ® results in the cleartext exposure of the connectivity association key (CAK). This issue is only applicable to PA-7500 Series devices which are in an NGFW cluster.
A user who possesses this key can read messages being sent between devices in a NGFW Cluster. There is no impact in non-clustered firewalls or clusters of firewalls that do not enable MACsec.
CVSS
No CVSS.
References
Link | Resource |
---|---|
https://security.paloaltonetworks.com/CVE-2025-2182 |
Configurations
No configuration.
History
13 Aug 2025, 17:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-08-13 17:15
Updated : 2025-08-13 17:33
NVD link : CVE-2025-2182
Mitre link : CVE-2025-2182
CVE.ORG link : CVE-2025-2182
JSON object : View
Products Affected
No product.
CWE
CWE-312
Cleartext Storage of Sensitive Information