CVE-2025-0108

HIGH CISA KEV EPSS 99.9%
Published Feb 12, 20251y ago · Modified Jun 17, 20261w ago
8.8 CVSS 4.0
High
Find Similar
Published Feb 12, 2025 1y ago
Last Modified Jun 17, 2026 1w ago
KEV Listed Feb 18, 2025 1y ago
KEV Due Mar 11, 2025 476d overdue

Description

An authentication bypass in the Palo Alto Networks PAN-OS software enables an unauthenticated attacker with network access to the management web interface to bypass the authentication otherwise required by the PAN-OS management web interface and invoke certain PHP scripts. While invoking these PHP scripts does not enable remote code execution, it can negatively impact integrity and confidentiality of PAN-OS. You can greatly reduce the risk of this issue by restricting access to the management web interface to only trusted internal IP addresses according to our recommended best practices deployment guidelines https://live.paloaltonetworks.com/t5/community-blogs/tips-amp-tricks-how-to-secure-the-management-access-of-your-palo/ba-p/464431 . This issue does not affect Cloud NGFW or Prisma Access software.

CVSS Details

Base Score
8.8
Exploitability
Impact
Vector string
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:C/RE:M/U:Red
Attack Vector Network
Attack Complexity Low
Privileges Required None
User Interaction None
Scope X

Threat Intelligence

CISA Known Exploited Overdue 476d
Added
Feb 18, 2025
Due
Mar 11, 2025

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

EPSS Exploit Probability
99.9% percentile
Exploit & Patch Status
Actively Exploited (KEV)
No Patch Available

Weaknesses 1

CWE-306 Missing Authentication for Critical Function Authentication

Affected Products 151

VendorProductVersionRange
paloaltonetworkspan-os*≥10.1.0  –  <10.1.14
paloaltonetworkspan-os*≥10.2.0  –  <10.2.7
paloaltonetworkspan-os*≥11.1.0  –  <11.1.2
paloaltonetworkspan-os*≥11.2.0  –  <11.2.4
paloaltonetworkspan-os10.1.14any
paloaltonetworkspan-os10.1.14any
paloaltonetworkspan-os10.1.14any
paloaltonetworkspan-os10.1.14any
paloaltonetworkspan-os10.1.14any
paloaltonetworkspan-os10.1.14any
paloaltonetworkspan-os10.1.14any
paloaltonetworkspan-os10.1.14any
paloaltonetworkspan-os10.1.14any
paloaltonetworkspan-os10.2.7any
paloaltonetworkspan-os10.2.7any
paloaltonetworkspan-os10.2.7any
paloaltonetworkspan-os10.2.7any
paloaltonetworkspan-os10.2.7any
paloaltonetworkspan-os10.2.7any
paloaltonetworkspan-os10.2.7any
paloaltonetworkspan-os10.2.7any
paloaltonetworkspan-os10.2.7any
paloaltonetworkspan-os10.2.7any
paloaltonetworkspan-os10.2.7any
paloaltonetworkspan-os10.2.7any
paloaltonetworkspan-os10.2.7any
paloaltonetworkspan-os10.2.7any
paloaltonetworkspan-os10.2.7any
paloaltonetworkspan-os10.2.7any
paloaltonetworkspan-os10.2.7any
paloaltonetworkspan-os10.2.7any
paloaltonetworkspan-os10.2.7any
paloaltonetworkspan-os10.2.7any
paloaltonetworkspan-os10.2.7any
paloaltonetworkspan-os10.2.7any
paloaltonetworkspan-os10.2.7any
paloaltonetworkspan-os10.2.7any
paloaltonetworkspan-os10.2.8any
paloaltonetworkspan-os10.2.8any
paloaltonetworkspan-os10.2.8any
paloaltonetworkspan-os10.2.8any
paloaltonetworkspan-os10.2.8any
paloaltonetworkspan-os10.2.8any
paloaltonetworkspan-os10.2.8any
paloaltonetworkspan-os10.2.8any
paloaltonetworkspan-os10.2.8any
paloaltonetworkspan-os10.2.8any
paloaltonetworkspan-os10.2.8any
paloaltonetworkspan-os10.2.8any
paloaltonetworkspan-os10.2.8any
paloaltonetworkspan-os10.2.8any
paloaltonetworkspan-os10.2.8any
paloaltonetworkspan-os10.2.8any
paloaltonetworkspan-os10.2.8any
paloaltonetworkspan-os10.2.8any
paloaltonetworkspan-os10.2.8any
paloaltonetworkspan-os10.2.8any
paloaltonetworkspan-os10.2.8any
paloaltonetworkspan-os10.2.9any
paloaltonetworkspan-os10.2.9any
paloaltonetworkspan-os10.2.9any
paloaltonetworkspan-os10.2.9any
paloaltonetworkspan-os10.2.9any
paloaltonetworkspan-os10.2.9any
paloaltonetworkspan-os10.2.9any
paloaltonetworkspan-os10.2.9any
paloaltonetworkspan-os10.2.9any
paloaltonetworkspan-os10.2.9any
paloaltonetworkspan-os10.2.9any
paloaltonetworkspan-os10.2.9any
paloaltonetworkspan-os10.2.9any
paloaltonetworkspan-os10.2.9any
paloaltonetworkspan-os10.2.9any
paloaltonetworkspan-os10.2.9any
paloaltonetworkspan-os10.2.9any
paloaltonetworkspan-os10.2.9any
paloaltonetworkspan-os10.2.9any
paloaltonetworkspan-os10.2.9any
paloaltonetworkspan-os10.2.10any
paloaltonetworkspan-os10.2.10any
paloaltonetworkspan-os10.2.10any
paloaltonetworkspan-os10.2.10any
paloaltonetworkspan-os10.2.10any
paloaltonetworkspan-os10.2.10any
paloaltonetworkspan-os10.2.10any
paloaltonetworkspan-os10.2.10any
paloaltonetworkspan-os10.2.10any
paloaltonetworkspan-os10.2.10any
paloaltonetworkspan-os10.2.10any
paloaltonetworkspan-os10.2.10any
paloaltonetworkspan-os10.2.10any
paloaltonetworkspan-os10.2.10any
paloaltonetworkspan-os10.2.11any
paloaltonetworkspan-os10.2.11any
paloaltonetworkspan-os10.2.11any
paloaltonetworkspan-os10.2.11any
paloaltonetworkspan-os10.2.11any
paloaltonetworkspan-os10.2.11any
paloaltonetworkspan-os10.2.11any
paloaltonetworkspan-os10.2.11any
paloaltonetworkspan-os10.2.11any
paloaltonetworkspan-os10.2.11any
paloaltonetworkspan-os10.2.11any
paloaltonetworkspan-os10.2.11any
paloaltonetworkspan-os10.2.12any
paloaltonetworkspan-os10.2.12any
paloaltonetworkspan-os10.2.12any
paloaltonetworkspan-os10.2.12any
paloaltonetworkspan-os10.2.12any
paloaltonetworkspan-os10.2.12any
paloaltonetworkspan-os10.2.13any
paloaltonetworkspan-os10.2.13any
paloaltonetworkspan-os10.2.13any
paloaltonetworkspan-os11.1.2any
paloaltonetworkspan-os11.1.2any
paloaltonetworkspan-os11.1.2any
paloaltonetworkspan-os11.1.2any
paloaltonetworkspan-os11.1.2any
paloaltonetworkspan-os11.1.2any
paloaltonetworkspan-os11.1.2any
paloaltonetworkspan-os11.1.2any
paloaltonetworkspan-os11.1.2any
paloaltonetworkspan-os11.1.2any
paloaltonetworkspan-os11.1.2any
paloaltonetworkspan-os11.1.2any
paloaltonetworkspan-os11.1.2any
paloaltonetworkspan-os11.1.2any
paloaltonetworkspan-os11.1.2any
paloaltonetworkspan-os11.1.2any
paloaltonetworkspan-os11.1.2any
paloaltonetworkspan-os11.1.2any
paloaltonetworkspan-os11.1.3any
paloaltonetworkspan-os11.1.4any
paloaltonetworkspan-os11.1.4any
paloaltonetworkspan-os11.1.4any
paloaltonetworkspan-os11.1.4any
paloaltonetworkspan-os11.1.4any
paloaltonetworkspan-os11.1.4any
paloaltonetworkspan-os11.1.4any
paloaltonetworkspan-os11.1.4any
paloaltonetworkspan-os11.1.4any
paloaltonetworkspan-os11.1.4any
paloaltonetworkspan-os11.1.4any
paloaltonetworkspan-os11.1.4any
paloaltonetworkspan-os11.1.4any
paloaltonetworkspan-os11.1.5any
paloaltonetworkspan-os11.1.6any
paloaltonetworkspan-os11.2.4any
paloaltonetworkspan-os11.2.4any
paloaltonetworkspan-os11.2.4any
paloaltonetworkspan-os11.2.4any

References 8

  • github.com https://github.com/iSee857/CVE-2025-0108-PoC
    ExploitThird Party Advisory
  • security.paloaltonetworks.com https://security.paloaltonetworks.com/CVE-2025-0108
    ExploitVendor Advisory
  • slcyber.io https://slcyber.io/blog/nginx-apache-path-confusion-to-auth-bypass-in-pan-os/
    ExploitPress/Media Coverage
  • bleepingcomputer.com https://www.bleepingcomputer.com/news/security/palo-alto-networks-tags-new-firewall-bug-as-exploited-in-attacks/
    Press/Media CoverageThird Party Advisory
  • cisa.gov https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-0108
    US Government Resource
  • darkreading.com https://www.darkreading.com/remote-workforce/patch-now-cisa-researchers-warn-palo-alto-flaw-exploited-wild
    Press/Media CoverageThird Party Advisory
  • securityweek.com https://www.securityweek.com/palo-alto-networks-confirms-exploitation-of-firewall-vulnerability/
    Press/Media CoverageThird Party Advisory
  • theregister.com https://www.theregister.com/2025/02/19/palo_alto_firewall_attack/
    Press/Media CoverageThird Party Advisory

Remediation

No remediation data recorded yet

Check vendor advisories and the NVD entry for patch availability.