PT-2025-6775 · Palo Alto Networks · Pan-Os Openconfig Plugin
Google Gdce
·
Published
2025-02-12
·
Updated
2025-02-23
·
CVE-2025-0110
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Palo Alto Networks PAN-OS (affected versions not specified)
Description
A command injection vulnerability in the Palo Alto Networks PAN-OS OpenConfig plugin enables an authenticated administrator to make gNMI requests to the PAN-OS management web interface, bypassing system restrictions and running arbitrary commands. The commands are executed as the " openconfig" user, which has the Device Administrator role on the firewall. To reduce the risk, restrict access to the management web interface to only trusted internal IP addresses.
Recommendations
As a temporary workaround, consider restricting access to the OpenConfig plugin until a patch is available.
Restrict access to the management web interface to only trusted internal IP addresses according to recommended best practices deployment guidelines.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Pan-Os Openconfig Plugin