CVE-2025-0108 Details
Description
An authentication bypass in the Palo Alto Networks PAN-OS software enables an unauthenticated attacker with network access to the management web interface to bypass the authentication otherwise required by the PAN-OS management web interface and invoke certain PHP scripts. While invoking these PHP scripts does not enable remote code execution, it can negatively impact integrity and confidentiality of PAN-OS. You can greatly reduce the risk of this issue by restricting access to the management web interface to only trusted internal IP addresses according to our recommended best practices deployment guidelines https://live.paloaltonetworks.com/t5/community-blogs/tips-amp-tricks-how-to-secure-the-management-access-of-your-palo/ba-p/464431 . This issue does not affect Cloud NGFW or Prisma Access software.
A vulnerability allowing authentication bypass has been identified in the management web interface of Palo Alto Networks PAN-OS. This flaw enables an unauthenticated attacker with network access to the management interface to bypass authentication and invoke certain PHP scripts. While this does not lead to remote code execution, it can adversely affect the integrity and confidentiality of the PAN-OS system. The vulnerability arises from a misconfiguration in the Nginx reverse proxy, which improperly handles authentication headers, allowing unauthorized access to PHP scripts that could be exploited to manipulate system data or settings.
Users are advised to upgrade to PAN-OS versions 10.1.14-h9, 10.2.13-h3, 11.1.6-h1, or 11.2.5. For versions 11.0 and older unsupported versions, upgrade to a supported fixed version. Additionally, restrict management interface access to trusted internal IP addresses.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Feb 19, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-0108 | CISA-ADP | US Government Resource |
| https://github.com/iSee857/CVE-2025-0108-PoC | CVE | ExploitThird Party Advisory |
| https://slcyber.io/blog/nginx-apache-path-confusion-to-auth-bypass-in-pan-os/ | CVE | ExploitPress/Media Coverage |
| https://www.bleepingcomputer.com/news/security/palo-alto-networks-tags-new-firewall-bug-as-exploited-in-attacks/ | CVE | Press/Media CoverageThird Party Advisory |
| https://www.darkreading.com/remote-workforce/patch-now-cisa-researchers-warn-palo-alto-flaw-exploited-wild | CVE | Press/Media CoverageThird Party Advisory |
| https://www.securityweek.com/palo-alto-networks-confirms-exploitation-of-firewall-vulnerability/ | CVE | Press/Media CoverageThird Party Advisory |
| https://www.theregister.com/2025/02/19/palo_alto_firewall_attack/ | CVE | Press/Media CoverageThird Party Advisory |
| https://security.paloaltonetworks.com/CVE-2025-0108 | [email protected] | ExploitVendor Advisory |
This CVE is in CISA's Known Exploited Vulnerabilities Catalog
Reference CISA's BOD 22-01 and Known Exploited Vulnerabilities Catalog for further guidance and requirements.
| Vulnerability Name | Date Added | Due Date | Required Action |
|---|---|---|---|
| Palo Alto Networks PAN-OS Authentication Bypass Vulnerability | Feb 18, 2025 | Mar 11, 2025 | Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-306 | Missing Authentication for Critical Function | [email protected] |
| CWE-306 | Missing Authentication for Critical Function | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| paloaltonetworks pan-os | >= 10.1.0, < 10.1.14 >= 10.2.0, < 10.2.7 >= 11.1.0, < 11.1.2 >= 11.2.0, < 11.2.4 10.1.14 - 10.1.14 h1 10.1.14 h2 10.1.14 h3 10.1.14 h4 10.1.14 h5 10.1.14 h6 10.1.14 h7 10.1.14 h8 10.2.7 - 10.2.7 h1 10.2.7 h10 10.2.7 h11 10.2.7 h12 10.2.7 h13 10.2.7 h14 10.2.7 h15 10.2.7 h16 10.2.7 h17 10.2.7 h18 10.2.7 h19 10.2.7 h2 10.2.7 h20 10.2.7 h21 10.2.7 h22 10.2.7 h23 10.2.7 h3 10.2.7 h4 10.2.7 h5 10.2.7 h6 10.2.7 h7 10.2.7 h8 10.2.7 h9 10.2.8 - 10.2.8 h1 10.2.8 h10 10.2.8 h11 10.2.8 h12 10.2.8 h13 10.2.8 h14 10.2.8 h15 10.2.8 h16 10.2.8 h17 10.2.8 h18 10.2.8 h19 10.2.8 h2 10.2.8 h20 10.2.8 h3 10.2.8 h4 10.2.8 h5 10.2.8 h6 10.2.8 h7 10.2.8 h8 10.2.8 h9 10.2.9 - 10.2.9 h1 10.2.9 h11 10.2.9 h12 10.2.9 h13 10.2.9 h14 10.2.9 h15 10.2.9 h16 10.2.9 h17 10.2.9 h18 10.2.9 h19 10.2.9 h2 10.2.9 h20 10.2.9 h3 10.2.9 h4 10.2.9 h5 10.2.9 h6 10.2.9 h7 10.2.9 h8 10.2.9 h9 10.2.10 - 10.2.10 h1 10.2.10 h10 10.2.10 h11 10.2.10 h12 10.2.10 h13 10.2.10 h2 10.2.10 h3 10.2.10 h4 10.2.10 h5 10.2.10 h6 10.2.10 h7 10.2.10 h8 10.2.10 h9 10.2.11 - 10.2.11 h1 10.2.11 h10 10.2.11 h11 10.2.11 h2 10.2.11 h3 10.2.11 h4 10.2.11 h5 10.2.11 h6 10.2.11 h7 10.2.11 h8 10.2.11 h9 10.2.12 - 10.2.12 h1 10.2.12 h2 10.2.12 h3 10.2.12 h4 10.2.12 h5 10.2.13 - 10.2.13 h1 10.2.13 h2 11.1.2 - 11.1.2 h1 11.1.2 h10 11.1.2 h11 11.1.2 h12 11.1.2 h13 11.1.2 h14 11.1.2 h15 11.1.2 h16 11.1.2 h17 11.1.2 h2 11.1.2 h3 11.1.2 h4 11.1.2 h5 11.1.2 h6 11.1.2 h7 11.1.2 h8 11.1.2 h9 11.1.3 11.1.4 - 11.1.4 h1 11.1.4 h10 11.1.4 h11 11.1.4 h12 11.1.4 h2 11.1.4 h3 11.1.4 h4 11.1.4 h5 11.1.4 h6 11.1.4 h7 11.1.4 h8 11.1.4 h9 11.1.5 11.1.6 - 11.2.4 - 11.2.4 h1 11.2.4 h2 11.2.4 h3 |
CPE
Remediation
| |
Change History
15 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 24, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Nov 4, 2025 | Modified Analysis | [email protected] |
| Oct 21, 2025 | CVE Modified | CISA-ADP |
| Oct 21, 2025 | CVE Modified | CISA-ADP |
| Oct 21, 2025 | CVE Modified | CISA-ADP |
| Jun 27, 2025 | Reanalysis | [email protected] |
| Apr 17, 2025 | Modified Analysis | [email protected] |
| Feb 20, 2025 | CVE Modified | CVE |
| Feb 20, 2025 | CVE CISA KEV Update | Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government |
| Feb 20, 2025 | CVE Modified | [email protected] |
| Feb 19, 2025 | Initial Analysis | [email protected] |
| Feb 19, 2025 | CVE CISA KEV Update | Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government |
| Feb 12, 2025 | New CVE Received | [email protected] |