CVE-2025-0129
Prisma Access Browser: Inappropriate control behavior in Prisma Access Browser
Severity
Critical 9.3
CVSS 4.0
Exploited
Not listed
EPSS
0.002
7.0th percentile
Discovered by
Third party
Published by the vendor
Published
Apr 11, 2025
Assigned by palo_alto
Description
An improper exception check in Palo Alto Networks Prisma Access Browser allows a low privileged user to prevent Prisma Access Browser from applying it's Policy Rules. This enables the user to use Prisma Access Browser without any restrictions.
Weakness: CWE-754
Affected products
| Vendor | Product | Category | Matched by |
|---|---|---|---|
| Palo Alto Networks | Prisma Access | SASE / SSE / Secure Web | cna-assigner |
Vendor-reported affected versions (1)
- Palo Alto Networks · Prisma Access Browser
Credit
Palo Alto Networks thanks Tan Inn Fung, Yu Ann Ong, Zhang Bosen from the GovTech Cybersecurity Group for discovering and reporting this issue.
Vendor remediation
CVEPrisma Access Browser CVE-2025-0129 132.83.3017.1