Executive brief
Palo Alto Networks Prisma SD-WAN ION devices, which are used to manage and secure corporate wide-area networks, contain a security flaw in how they verify digital certificates. An attacker positioned on the local network could exploit this to impersonate the central management controller. If successful, this could allow the attacker to intercept sensitive data, modify network configurations, or disrupt connectivity.
Technical details
An improper certificate validation vulnerability (CWE-295) exists in the Palo Alto Networks Prisma SD-WAN ION software. The flaw stems from the device failing to correctly validate the identity of the controller during communication. An attacker with adjacent network access can exploit this to perform a man-in-the-middle (MitM) attack, allowing them to impersonate the controller and intercept or modify traffic. The vulnerability is addressed in versions 6.3.6-b10, 6.4.3-b8, and 6.5.3-b15 or later.
Affected products
- Palo Alto Networks Prisma SD-WAN ION 6.3.1 to 6.3.6-b10; 6.4.1 to 6.4.3-b8; 6.5.1 to 6.5.3-b15
Timeline
- 2026-05-13: disclosed: Initial publication by Palo Alto Networks
- 2026-05-13: patched: Fixes released in updated software versions