CVE-2025-0124 Details
Description
An authenticated file deletion vulnerability in the Palo Alto Networks PAN-OS® software enables an authenticated attacker with network access to the management web interface to delete certain files as the “nobody” user; this includes limited logs and configuration files but does not include system files. The attacker must have network access to the management web interface to exploit this issue. You greatly reduce the risk of this issue by restricting access to the management web interface to only trusted internal IP addresses according to our recommended critical deployment guidelines https://live.paloaltonetworks.com/t5/community-blogs/tips-amp-tricks-how-to-secure-the-management-access-of-your-palo/ba-p/464431 . This issue affects Cloud NGFW. However, this issue does not affect Prisma® Access software.
A file deletion vulnerability has been identified in Palo Alto Networks PAN-OS software, specifically within the Cloud NGFW product. This vulnerability allows an authenticated attacker with network access to the management web interface to delete certain files, including limited logs and configuration files, as the 'nobody' user. However, system files are not affected. The vulnerability arises from external control of file names or paths, enabling unauthorized file manipulation. To exploit this issue, an attacker must have network access to the management web interface. It is important to note that this vulnerability does not impact Prisma Access software.
Users are advised to upgrade to a supported fixed version of PAN-OS. For specific version upgrade recommendations, please refer to the official Palo Alto Networks guidance. Additionally, it is recommended to secure access to the management interface by restricting it to trusted internal IP addresses.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 11, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://security.paloaltonetworks.com/CVE-2025-0124 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-73 | External Control of File Name or Path | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| paloaltonetworks pan-os | >= 10.1.0, < 10.1.14 >= 10.2.0, < 10.2.10 >= 11.0.0, < 11.0.6 >= 11.1.0, < 11.1.5 >= 11.2.0, < 11.2.1 10.1.14 - 10.1.14 h1 10.1.14 h10 10.1.14 h2 10.1.14 h3 10.1.14 h4 10.1.14 h5 10.1.14 h6 10.1.14 h7 10.1.14 h8 10.1.14 h9 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Oct 2, 2025 | Initial Analysis | [email protected] |
| Apr 11, 2025 | New CVE Received | [email protected] |