CVE-2025-0137 Details
Description
An improper input neutralization vulnerability in the management web interface of the Palo Alto Networks PAN-OS® software enables a malicious authenticated read-write administrator to impersonate another legitimate authenticated PAN-OS administrator. The attacker must have network access to the management web interface to exploit this issue. You greatly reduce the risk of this issue by restricting access to the management web interface to only trusted internal IP addresses according to our recommended critical deployment guidelines https://live.paloaltonetworks.com/t5/community-blogs/tips-amp-tricks-how-to-secure-the-management-access-of-your-palo/ba-p/464431 .
A vulnerability allowing improper input neutralization has been identified in the management web interface of Palo Alto Networks PAN-OS software. This vulnerability enables a malicious authenticated read-write administrator to impersonate another legitimate authenticated PAN-OS administrator. Exploitation requires network access to the management web interface.
Administrators are advised to upgrade to PAN-OS versions 11.2.5, 11.1.8, 10.2.13, or 10.1.14-h14. For all other unsupported PAN-OS versions, upgrade to a supported fixed version. Additionally, restrict management web interface access to trusted internal IP addresses, following Palo Alto Networks' critical deployment guidelines.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed May 14, 2025CISA-ADP
Assessed May 14, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://security.paloaltonetworks.com/CVE-2025-0137 | [email protected] | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-83 | Improper Neutralization of Script in Attributes in a Web Page | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Palo Alto Networks PAN-OS | >= 11.2.0, <= 11.2.4 (semver) >= 11.1.0, <= 11.1.7 (semver) >= 10.2.0, <= 10.2.12 (semver) >= 10.1.0, <= 10.1.14-h14 (semver) |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 14, 2025 | New CVE Received | [email protected] |
Volerion