CVE-2025-0111
KEVlargeAuthenticated File Read in Palo Alto Networks PAN-OS Management Interface
CISA: Palo Alto Networks PAN-OS File Read Vulnerability
CVE-2025-0111 is an authenticated arbitrary file read vulnerability in Palo Alto Networks PAN-OS, reachable through the firewall's management web interface (CWE-73/CWE-610). An attacker who already has low-privileged credentials and network access to the management interface can craft requests to read files on the PAN-OS filesystem that are readable by the "nobody" user, potentially exposing configuration and other sensitive data. Only appliances running PAN-OS with a reachable management interface are affected; Palo Alto Networks states the flaw does not affect Cloud NGFW or Prisma Access. CISA added the flaw to its Known Exploited Vulnerabilities catalog on 2025-02-20, and the vendor has warned that it is being actively exploited, with headlines indicating attackers are chaining it with other PAN-OS flaws (such as the separately patched CVE-2025-0108 authentication bypass). No public proof-of-concept exploit is known, and EPSS estimates a 2.0% chance of exploitation in the next 30 days (80th percentile).
What to do: Apply the PAN-OS patch identified in the Palo Alto Networks security advisory for CVE-2025-0111; since this is a KEV entry (added 2025-02-20), federal agencies must remediate per vendor instructions or discontinue use by the required deadline. As an interim mitigation, restrict access to the management web interface to trusted internal IP addresses per the vendor's best-practice deployment guidance, and verify no management interface is exposed to the internet. Hunt management-interface logs for anomalous authenticated activity, as attackers have been observed chaining this flaw with other PAN-OS vulnerabilities.
| Palo Alto Networks PAN-OS | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
An authenticated file read vulnerability in the Palo Alto Networks PAN-OS software enables an authenticated attacker with network access to the management web interface to read files on the PAN-OS filesystem that are readable by the “nobody” user. You can greatly reduce the risk of this issue by restricting access to the management web interface to only trusted internal IP addresses according to our recommended best practices deployment guidelines https://live.paloaltonetworks.com/t5/community-blogs/tips-amp-tricks-how-to-secure-the-management-access-of-your-palo/ba-p/464431 . This issue does not affect Cloud NGFW or Prisma Access software.
- Affected
- Palo Alto Networks PAN-OS
- Required action
- Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
- Due date
- Ransomware use
- Unknown
- Vendors
- paloaltonetworks
- Products
- pan-os
- Weakness
- CWE-73, CWE-610
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:C/RE:M/U:Red