CVE-2025-0108Critical· 9.1▾ Hadal⚠ Exploited in the wildPoC availableAn authentication bypass in the Palo Alto Networks PAN-OS software enables an unauthenticated attacker with network access to the management web interface to bypass the authentication otherwise required by the PAN-OS management web inter…
▾ Hadal zone — Critical and actively exploited (CISA KEV / 0day)
impact 50.1 · likelihood 19.7 · exploitation 25
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Public exploit / PoC code seen in 2 sources. Availability, not in-the-wild use.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Federal remediation due Mar 11, 2025
Last analysed / modified upstream
98%
7 GitHub repos · Nuclei ×1 (last check)
Added to the CISA catalog on Feb 18, 2025. Federal remediation due Mar 11, 2025. View catalog ↗
An authentication bypass in the Palo Alto Networks PAN-OS software enables an unauthenticated attacker with network access to the management web interface to bypass the authentication otherwise required by the PAN-OS management web interface and invoke certain PHP scripts. While invoking these PHP scripts does not enable remote code execution, it can negatively impact integrity and confidentiality of PAN-OS.
You can greatly reduce the risk of this issue by restricting access to the management web interface to only trusted internal IP addresses according to our recommended best practices deployment guidelines https://live.paloaltonetworks.com/t5/community-blogs/tips-amp-tricks-how-to-secure-the-management-access-of-your-palo/ba-p/464431 .
This issue does not affect Cloud NGFW or Prisma Access software.
pan-os >= 10.1.0, < 10.1.14pan-os >= 10.2.0, < 10.2.7pan-os >= 11.1.0, < 11.1.2pan-os >= 11.2.0, < 11.2.4pan-os = 10.1.14pan-os = 10.2.7pan-os = 10.2.8pan-os = 10.2.9pan-os = 10.2.10pan-os = 10.2.11pan-os = 10.2.12pan-os = 10.2.13pan-os = 11.1.2pan-os = 11.1.3pan-os = 11.1.4pan-os = 11.1.5pan-os = 11.1.6pan-os = 11.2.4Upgrade past the affected range:
pan-os 11.2.4Connected by shared product, vendor, weakness, or advisory.
CVE-2024-0012Critical· 9.8An authentication bypass in Palo Alto Networks PAN-OS software enables an unauthenticated attacker with network access to the management web interface to gain PAN-OS administrator privileges to perform administrative actions, tamper with…
CVE-2019-1579High· 8.1Remote Code Execution in PAN-OS 7.1.18 and earlier, PAN-OS 8.0.11-h1 and earlier, and PAN-OS 8.1.2 and earlier with GlobalProtect Portal or GlobalProtect Gateway Interface enabled may allow an unauthenticated remote attacker to execute a…
CVE-2024-9474High· 7.2A privilege escalation vulnerability in Palo Alto Networks PAN-OS software allows a PAN-OS administrator with access to the management web interface to perform actions on the firewall with root privileges. Cloud NGFW and Prisma Access a…
CVE-2019-5591Medium· 6.5A Default Configuration vulnerability in FortiOS may allow an unauthenticated attacker on the same subnet to intercept sensitive information by impersonating the LDAP server.
CVE-2024-51567Critical· 10.0upgrademysqlstatus in databases/views.py in CyberPanel (aka Cyber Panel) before 5b08cd6 allows remote attackers to bypass authentication and execute arbitrary commands via /dataBases/upgrademysqlstatus by bypassing secMiddleware (which i…
CVE-2025-3248Critical· 9.8Langflow versions prior to 1.3.0 are susceptible to code injection in the /api/v1/validate/code endpoint