PAN-OS 10.2.13-h3 Addressed Issues
Table of Contents
Expand All
|
Collapse All
Next-Generation Firewall Docs
-
-
- PAN-OS 11.1 & Later
- PAN-OS 11.0 (EoL)
- PAN-OS 10.2
- PAN-OS 10.1
- PAN-OS 10.0 (EoL)
- PAN-OS 9.1 (EoL)
- Cloud Management of NGFWs
-
- PAN-OS 11.1 & Later
- PAN-OS 11.0 (EoL)
- PAN-OS 10.2
- PAN-OS 10.1
-
-
- PAN-OS 11.2
- PAN-OS 11.1
- PAN-OS 11.0 (EoL)
- PAN-OS 10.2
- PAN-OS 10.1
- PAN-OS 10.0 (EoL)
- PAN-OS 9.1 (EoL)
- PAN-OS 9.0 (EoL)
- PAN-OS 8.1 (EoL)
- Cloud Management and AIOps for NGFW
PAN-OS 10.2.13-h3 Addressed Issues
Addressed issues for the PAN-OS 10.2.13-h3 general available hotfix
release.
Issue ID
|
Description
|
---|---|
PAN-274570
|
Fixed an issue where the devsrvr process restarted after
a failed commit due to an invalid memory access.
|
PAN-273994
|
A fix was made to address CVE-2025-0111.
|
PAN-273971
|
A fix was made to address CVE-2025-0108.
|
PAN-273278
|
A fix was made to address CVE-2025-0109.
|
PAN-273215
|
Fixed an issue where a syntax error in the index generation script
caused a high management plane CPU load after upgrading.
|
PAN-273021
|
Fixed an issue where 25G port links did not come up due to a change
in the handling of 25G DAC modules.
|
PAN-271926
|
Fixed an issue where TLS 1.3 decryption failed with a bad record MAC
error when the firewall was configured to decrypt and inspect TLS
traffic.
|
PAN-270549
|
Fixed an issue where early TLS data was not handled correctly by the
accumulation proxy.
|
PAN-269899
|
Fixed an issue where the Panorama web interface was slower than
expected when querying for device tags.
|
PAN-269731
|
Fixed an issue where Panorama did not display logs from firewalls
after upgrading to PAN-OS 10.2.11 on devices due to Elasticsearch
(ES) getting restarted continuously.
|
PAN-269624
|
Fixed an issue where GlobalProtect clients failed to connect with the
error message The device or feature requires a
GlobalProtect subscription license.
|
PAN-268972
|
Fixed an issue where Panorama was slower than expected when using a
high number of device group tags in a non-shared context.
|
PAN-268909
|
Fixed an issue where IP address tags were removed from firewalls
after a management server or useridd process restart.
This occurred when a Panorama serial-number based configuration was
used for User-ID redistribution.
|
PAN-268727
|
Fixed an issue where traffic was dropped when the accumulation proxy
was enabled and header insertion modified packets.
|
PAN-268319
|
Fixed an issue where Receive Time and
Time Generated were not visible as
attributes in the Filter Builder for system
logs and URL filtering logs.
|
PAN-268260
|
Fixed an issue on hardware firewalls where, when SSL decryption was
enabled and Client Hello messages spanned multiple TCP segments,
some SSL decrypted sessions failed.
|
PAN-267781
| Fixed an issue where Panorama did not display the Source Dynamic Address Group. |
PAN-267001
|
Fixed an issue where multicast streams were unstable with ECMP and
dropped every 30 seconds.
|
PAN-266312
|
Fixed an issue where BFD sessions took longer than expected to
establish after an HA failover due to BGP.
|
PAN-265179
|
Fixed an issue where a kernel race condition caused the firewall to
reboot with a kernel panic.
|
PAN-261739
| (VM-Series firewalls in Microsoft Azure environments only) Fixed an issue where the firewall displayed 0 for the physical port counters read from MAC. |
PAN-259002
|
Fixed an issue where frequent external dynamic list updates caused
the configd process to restart.
|
PAN-256051
|
Fixed an issue on the firewall where enabling flow basic caused the
firewall to stop responding due to a masterd process
restart.
|
PAN-249597
|
Fixed an issue where the Policy page on the
Panorama web interface was slower than expected when a device group
had a large number of managed devices.
|
PAN-246949
|
Fixed an issue where custom admin users were not able to click
OK in the push scope selection window
when device group or template were disabled under commit in the
admin roles.
|
PAN-240739
|
Fixed an issue where the ECMP FIB update on the dataplane didn't
clear the pending change flag, which caused the next non-ECMP FIB
update to miss the latest generation ID and age out after 5
minutes
|
PAN-225213
|
Fixed an issue where Push All Changes
displayed changes that were already committed in the push scope for
another device group after performing a selective commit and
selective push to the first device group.
|
PAN-215038
|
Fixed an issue where the output of the request
logging-service-forwarding status CLI command did
not display the correct information after successfully onboarding a
firewall to Cloud Delivered Licensing (CDL).
|