Web sessions in the web interface of Palo Alto Networks Prisma® Cloud Compute Edition do not expire when users are deleted, which makes Prisma Cloud Compute Edition susceptible to unauthorized access.
Compute in Prisma Cloud Enterprise Edition is not affected by this issue.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://security.paloaltonetworks.com/CVE-2025-0138 |
![]() ![]() |
History
Wed, 14 May 2025 20:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Wed, 14 May 2025 18:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Web sessions in the web interface of Palo Alto Networks Prisma® Cloud Compute Edition do not expire when users are deleted, which makes Prisma Cloud Compute Edition susceptible to unauthorized access. Compute in Prisma Cloud Enterprise Edition is not affected by this issue. | |
Title | Prisma Cloud Compute Edition: Insufficient Session Expiration Vulnerability in the Web Interface | |
First Time appeared |
Paloaltonetworks
Paloaltonetworks prisma Cloud Compute Edition |
|
Weaknesses | CWE-613 | |
CPEs | cpe:2.3:a:paloaltonetworks:prisma_cloud_compute_edition:32.04.113:*:*:*:*:*:*:* cpe:2.3:a:paloaltonetworks:prisma_cloud_compute_edition:32.05.124:*:*:*:*:*:*:* cpe:2.3:a:paloaltonetworks:prisma_cloud_compute_edition:32.06.113:*:*:*:*:*:*:* cpe:2.3:a:paloaltonetworks:prisma_cloud_compute_edition:32.07.123:*:*:*:*:*:*:* cpe:2.3:a:paloaltonetworks:prisma_cloud_compute_edition:33.01.137:*:*:*:*:*:*:* cpe:2.3:a:paloaltonetworks:prisma_cloud_compute_edition:33.02.134:*:*:*:*:*:*:* cpe:2.3:a:paloaltonetworks:prisma_cloud_compute_edition:33.03.138:*:*:*:*:*:*:* cpe:2.3:a:paloaltonetworks:prisma_cloud_compute_edition:34.00.137:*:*:*:*:*:*:* |
|
Vendors & Products |
Paloaltonetworks
Paloaltonetworks prisma Cloud Compute Edition |
|
References |
| |
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: palo_alto
Published: 2025-05-14T18:10:16.979Z
Updated: 2025-05-14T19:45:01.477Z
Reserved: 2024-12-20T23:24:41.254Z
Link: CVE-2025-0138

Updated: 2025-05-14T19:44:53.690Z

Status : Awaiting Analysis
Published: 2025-05-14T19:15:52.370
Modified: 2025-05-16T14:43:56.797
Link: CVE-2025-0138

No data.