PT-2025-1074 · Palo Alto Networks · Palo Alto Networks Expedition

Published

2025-01-08

·

Updated

2026-01-23

·

CVE-2025-0105

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions Palo Alto Networks Expedition (affected versions not specified)
Description The issue is related to an arbitrary file deletion vulnerability in Palo Alto Networks Expedition. This vulnerability allows an unauthenticated attacker to delete arbitrary files accessible to the www-data user on the host filesystem. The vulnerability is also associated with incorrect external control of a file name or path, which can be exploited by a remote attacker to delete files.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Weakness Enumeration

Related Identifiers

BDU:2025-00309
CVE-2025-0105

Affected Products

Palo Alto Networks Expedition