PT-2025-6473 · Palo Alto Networks · Pan-Os

Adam Kues

·

Published

2025-02-12

·

Updated

2026-05-24

·

CVE-2025-0108

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Palo Alto Networks PAN-OS (affected versions not specified)
Description An authentication bypass in the management web interface allows an unauthenticated attacker with network access to bypass required authentication and invoke specific PHP scripts. This issue stems from path confusion between Nginx and Apache. While it does not enable remote code execution, it can negatively impact the integrity and confidentiality of the system, allowing attackers to extract sensitive system data, recover firewall configurations, or manipulate certain settings. Approximately 4,400 devices have been identified as exposing their management interface to the internet, and active exploitation has been observed since February 13.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability. Restrict access to the management web interface to only trusted internal IP addresses.

Exploit

DoS

RCE

Missing Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-01567
CVE-2025-0108
PANOS_CVE2025_0108
PROFTPCVE_2010_20103

Affected Products

Pan-Os