PT-2025-6473 · Palo Alto Networks · Pan-Os
Adam Kues
·
Published
2025-02-12
·
Updated
2026-05-24
·
CVE-2025-0108
CVSS v3.1
9.1
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Palo Alto Networks PAN-OS (affected versions not specified)
Description
An authentication bypass in the management web interface allows an unauthenticated attacker with network access to bypass required authentication and invoke specific PHP scripts. This issue stems from path confusion between Nginx and Apache. While it does not enable remote code execution, it can negatively impact the integrity and confidentiality of the system, allowing attackers to extract sensitive system data, recover firewall configurations, or manipulate certain settings. Approximately 4,400 devices have been identified as exposing their management interface to the internet, and active exploitation has been observed since February 13.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Restrict access to the management web interface to only trusted internal IP addresses.
Exploit
DoS
RCE
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Pan-Os