PAN-OS: Authentication Bypass in the Management Web Interface
- Severity
- Critical9.1CVSS 3.1, Critical
- EPSS
- 98%
- Published
- 12 Feb 2025
- Updated
- 24 Sept 2026
Description
Title, description and vendor guidance are quoted from the source records.
An authentication bypass in the Palo Alto Networks PAN-OS software enables an unauthenticated attacker with network access to the management web interface to bypass the authentication otherwise required by the PAN-OS management web interface and invoke certain PHP scripts. While invoking these PHP scripts does not enable remote code execution, it can negatively impact integrity and confidentiality of PAN-OS. You can greatly reduce the risk of this issue by restricting access to the management web interface to only trusted internal IP addresses according to our recommended best practices deployment guidelines https://live.paloaltonetworks.com/t5/community-blogs/tips-amp-tricks-how-to-secure-the-management-access-of-your-palo/ba-p/464431 . This issue does not affect Cloud NGFW or Prisma Access software.
Weakness: CWE-306
Known exploited
Added to CISA KEV on 18 Feb 2025
Federal remediation due date: 11 Mar 2025
Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Exploit prediction
98% probability of exploitation in the next 30 days (percentile 100%).
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
What the source states, per branch
Versions matched by Patcharo
Palo Alto Networks PAN-OSSource: Palo Alto Networks (CVE record)
| Branch | Affected | Fixed in |
|---|---|---|
| 11.2 | >= 11.2.0, < 11.2.4-h4 | 11.2.4-h4 |
| 11.1 | >= 11.1.0, < 11.1.2-h18 >= 11.1.3, < 11.1.6-h1 | 11.1.2-h18 11.1.6-h1 |
| 10.2 | >= 10.2.0, < 10.2.7-h24 >= 10.2.8, < 10.2.8-h21 >= 10.2.9, < 10.2.9-h21 >= 10.2.10, < 10.2.10-h14 >= 10.2.11, < 10.2.11-h12 >= 10.2.12, < 10.2.12-h6 >= 10.2.13, < 10.2.13-h3 | 10.2.7-h24 10.2.8-h21 10.2.9-h21 10.2.10-h14 10.2.11-h12 10.2.12-h6 10.2.13-h3 |
| 10.1 | >= 10.1.0, < 10.1.14-h9 | 10.1.14-h9 |
Versions not listed are stated unaffected by the vendor.
Workaround / Vendor remediation
Workaround · PAN-OS
Recommended mitigation—The vast majority of firewalls already follow Palo Alto Networks and industry best practices. However, if you have not already, we strongly recommend that you secure access to your management interface according to our https://live.paloaltonetworks.com/t5/community-blogs/tips-amp-tricks-how-to-secure-the-management-access-of-your-palo/ba-p/464431 * Palo Alto Networks official and detailed technical documentation: https://docs.paloaltonetworks.com/best-practices/10-1/administrative-access-best-practices/administrative-access-best-practices/deploy-administrative-access-best-practices Additionally, customers with a Threat Prevention subscription can block attacks for this vulnerability by enabling Threat ID 510000 and 510001 (introduced in Applications and Threats content version 8943).
Vendor remediation · PAN-OS
Version Minor Version Suggested Solution PAN-OS 10.1 10.1.0 through 10.1.14 Upgrade to 10.1.14-h9 or later PAN-OS 10.2 10.2.0 through 10.2.13 Upgrade to 10.2.13-h3 or later 10.2.7Upgrade to 10.2.7-h24 or 10.2.13-h3 or later 10.2.8Upgrade to 10.2.8-h21 or 10.2.13-h3 or later 10.2.9Upgrade to 10.2.9-h21 or 10.2.13-h3 or later 10.2.10Upgrade to 10.2.10-h14 or 10.2.13-h3 or later 10.2.11Upgrade to 10.2.11-h12 or 10.2.13-h3 or later 10.2.12Upgrade to 10.2.12-h6 or 10.2.13-h3 or later PAN-OS 11.0 (EoL) Upgrade to a supported fixed versionPAN-OS 11.1 11.1.0 through 11.1.6 Upgrade to 11.1.6-h1 or later 11.1.2Upgrade to 11.1.2-h18 or 11.1.6-h1 or later PAN-OS 11.2 11.2.0 through 11.2.4 Upgrade to 11.2.4-h4 or laterNote: PAN-OS 11.0 reached end of life (EoL) on November 17, 2024. No additional fixes are planned for this release.
References
- https://security.paloaltonetworks.com/CVE-2025-0108(opens in a new tab)
- https://github.com/iSee857/CVE-2025-0108-PoC(opens in a new tab)
- https://slcyber.io/blog/nginx-apache-path-confusion-to-auth-bypass-in-pan-os/(opens in a new tab)
- https://www.bleepingcomputer.com/news/security/palo-alto-networks-tags-new-firewall-bug-as-exploited-in-attacks/(opens in a new tab)
- https://www.darkreading.com/remote-workforce/patch-now-cisa-researchers-warn-palo-alto-flaw-exploited-wild(opens in a new tab)
- https://www.securityweek.com/palo-alto-networks-confirms-exploitation-of-firewall-vulnerability/(opens in a new tab)
- https://www.theregister.com/2025/02/19/palo_alto_firewall_attack/(opens in a new tab)
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-0108(opens in a new tab)
Provenance
Every fact on this page comes from the sources below. Nothing is written by an AI.
- Palo Alto Networks (CVE record)
- Palo Alto Networks (CVE record) · 27 Sept 2026, 23:46 UTC · Parser patcharo-cve5/1.1.0
- CISA Known Exploited Vulnerabilities
- CISA Known Exploited Vulnerabilities · 27 Sept 2026, 23:42 UTC · Parser patcharo-kev/1.0.0
- NVD
- NVD · 27 Sept 2026, 23:44 UTC · Parser patcharo-nvd/1.0.0
- FIRST EPSS
- FIRST EPSS · 27 Sept 2026, 23:46 UTC · Parser patcharo-epss/1.0.0
Last verified: 28 Sept 2026, 02:31 UTC