PT-2025-21213 · Palo Alto Networks · Pan-Os

A Customer

·

Published

2025-05-14

·

Updated

2025-05-14

·

CVE-2025-0137

CVSS v2.0

5.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions: PAN-OS (affected versions not specified)
Description: An improper input neutralization issue in the management web interface of the Palo Alto Networks PAN-OS software allows a malicious authenticated read-write administrator to impersonate another legitimate authenticated PAN-OS administrator. The attacker must have network access to the management web interface to exploit this issue.
Recommendations: Restrict access to the management web interface to only trusted internal IP addresses according to the recommended critical deployment guidelines. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Weakness Enumeration

Related Identifiers

BDU:2025-05704
CVE-2025-0137

Affected Products

Pan-Os