Files
2026-05-28 08:11:36 -05:00

3.2 KiB

type, product, version
type product version
Addressed PAN-OS 11.2.12

BLANK-000000

Fixes were made to address the following CVEs:

PAN-325120

Fixed an issue on PA-415, PA-415-5G, PA-445, PA-455, and PA-455-5G platforms where certain PAN-OS versions caused intermittent connectivity failures on the Eth1/1 data port and loss of power on PoE ports.

PAN-322815

VM-Series firewalls on Microsoft Azure environments only

Fixed an issue where the firewall entered maintenance mode after enabling FIPS-CC mode and rebooted.

PAN-318275

VM-Series firewalls only

Fixed an issue where the firewall became unresponsive and did not automatically reboot, which led to prolonged outages. With this fix, the Linux kernel configuration will trigger a system panic and reboot.

PAN-317583

Fixed an issue with intermittent ICMP ping drops and packet loss in traffic flows between a hub and branch after upgrading to an affected PAN-OS release due to incorrect SD-WAN path monitor state.

PAN-315912

Fixed an issue where the Maximum Segment Size (MSS) rewrite functionality for packets ingressing through SD-WAN interfaces on firewalls was not optimized.

PAN-315176

Added an enable and disable CLI command to address an issue where the firewall experienced increased packet drops and slower performance after an upgrade due to high burst traffic.

PAN-314319

Added a CLI command to enable and disable AHO software offload optimization.

PAN-314147

Fixed an issue where SSL traffic was dropped on SD-WAN DIA interfaces with member having different MTU.

PAN-314018

VM-Series firewalls in AWS environments only

Fixed an issue where the decrypt mirror port did not function expected, which prevented decrypted traffic from reaching the intended destination collector.

PAN-313700

Fixed an issue where an unexpected reboot occurred when Inline Cloud Analysis was enabled in an Anti-Spyware and Vulnerability profile.

PAN-313216

Fixed an issue where firewalls with Prisma Access incorrectly displayed some traffic as unsanctioned in traffic logs for cloud applications that were tagged as sanctioned.

PAN-312514

Fixed an issue where correlation logs were not forwarded via syslog or email.

PAN-312354

Fixed an issue where Captive Portal authentication redirects failed for HTTPS traffic when a user attempted to access internal HTTPS websites via URL, which led to ERR_CONNECTION_RESET error messages in the browser with SSL decryption and CTD handshake inspection enabled.