ZeroHour

CVE-2025-0111

KEVlarge

Authenticated File Read in Palo Alto Networks PAN-OS Management Interface

CISA: Palo Alto Networks PAN-OS File Read Vulnerability

CVSS 4.0
7.1 high
EPSS
2%p80
Published
()
KEV added
AI analysis

CVE-2025-0111 is an authenticated arbitrary file read vulnerability in Palo Alto Networks PAN-OS, reachable through the firewall's management web interface (CWE-73/CWE-610). An attacker who already has low-privileged credentials and network access to the management interface can craft requests to read files on the PAN-OS filesystem that are readable by the "nobody" user, potentially exposing configuration and other sensitive data. Only appliances running PAN-OS with a reachable management interface are affected; Palo Alto Networks states the flaw does not affect Cloud NGFW or Prisma Access. CISA added the flaw to its Known Exploited Vulnerabilities catalog on 2025-02-20, and the vendor has warned that it is being actively exploited, with headlines indicating attackers are chaining it with other PAN-OS flaws (such as the separately patched CVE-2025-0108 authentication bypass). No public proof-of-concept exploit is known, and EPSS estimates a 2.0% chance of exploitation in the next 30 days (80th percentile).

What to do: Apply the PAN-OS patch identified in the Palo Alto Networks security advisory for CVE-2025-0111; since this is a KEV entry (added 2025-02-20), federal agencies must remediate per vendor instructions or discontinue use by the required deadline. As an interim mitigation, restrict access to the management web interface to trusted internal IP addresses per the vendor's best-practice deployment guidance, and verify no management interface is exposed to the internet. Hunt management-interface logs for anomalous authenticated activity, as attackers have been observed chaining this flaw with other PAN-OS vulnerabilities.

Affected
Palo Alto Networks PAN-OS
Estimated exposure
largeon the order of tens of thousands of internet-exposed PAN-OS management interfaces, with the broader PAN-OS installed base plausibly in the hundreds of… — Public internet scans of the PAN-OS management interface (tracked during the early-2025 PAN-OS exploitation wave) have shown on the order of tens of thousands of exposed instances, and the vendor's large enterprise firewall market share…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

An authenticated file read vulnerability in the Palo Alto Networks PAN-OS software enables an authenticated attacker with network access to the management web interface to read files on the PAN-OS filesystem that are readable by the “nobody” user. You can greatly reduce the risk of this issue by restricting access to the management web interface to only trusted internal IP addresses according to our recommended best practices deployment guidelines https://live.paloaltonetworks.com/t5/community-blogs/tips-amp-tricks-how-to-secure-the-management-access-of-your-palo/ba-p/464431 . This issue does not affect Cloud NGFW or Prisma Access software.

CISA Known Exploited Vulnerability
Affected
Palo Alto Networks PAN-OS
Required action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
paloaltonetworks
Products
pan-os
Weakness
CWE-73, CWE-610
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:C/RE:M/U:Red

In the news