An improper exception check in Palo Alto Networks Prisma Access Browser allows a low privileged user to prevent Prisma Access Browser from applying it's Policy Rules. This enables the user to use Prisma Access Browser without any restrictions.
History

Fri, 13 Jun 2025 21:00:00 +0000

Type Values Removed Values Added
Metrics cvssV4_0

{'score': 8.4, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/AU:N/R:U/V:D/RE:L/U:Amber'}

cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N/AU:N/R:U/V:D/RE:L/U:Amber'}


Wed, 21 May 2025 00:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-754

Tue, 20 May 2025 23:45:00 +0000

Type Values Removed Values Added
Description Prisma Access Browser: Inappropriate control behavior in Prisma Access Browser An improper exception check in Palo Alto Networks Prisma Access Browser allows a low privileged user to prevent Prisma Access Browser from applying it's Policy Rules. This enables the user to use Prisma Access Browser without any restrictions.
Metrics cvssV4_0

{'score': 9.4, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/AU:N/R:U/V:D/RE:L/U:Amber'}

cvssV4_0

{'score': 8.4, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/AU:N/R:U/V:D/RE:L/U:Amber'}


Tue, 15 Apr 2025 15:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-306
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 11 Apr 2025 22:45:00 +0000

Type Values Removed Values Added
Description Prisma Access Browser: Inappropriate control behavior in Prisma Access Browser
Title Prisma Access Browser: Inappropriate control behavior in Prisma Access Browser
References
Metrics cvssV4_0

{'score': 9.4, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/AU:N/R:U/V:D/RE:L/U:Amber'}


cve-icon MITRE

Status: PUBLISHED

Assigner: palo_alto

Published: 2025-04-11T22:25:36.346Z

Updated: 2025-06-13T20:50:34.590Z

Reserved: 2024-12-20T23:23:29.801Z

Link: CVE-2025-0129

cve-icon Vulnrichment

Updated: 2025-04-14T17:07:14.695Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-04-11T23:15:28.337

Modified: 2025-06-13T21:15:19.467

Link: CVE-2025-0129

cve-icon Redhat

No data.