ZeroHour
Help Net Securitypublished ()ingested @zeljkazorz

PAN-OS authentication bypass hole plugged, PoC is public (CVE-2025-0108)

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-0012
+1 in the same advisory: …9474
Authentication Bypass in Palo Alto Networks PAN-OS Management Interface

CVE-2024-0012 is a critical authentication bypass (CWE-306) in the web management interface of Palo Alto Networks PAN-OS that lets an unauthenticated attacker with network access to that interface gain full PAN-OS administrator privileges. It is triggered simply by sending requests to an exposed management web interface, with no credentials or user interaction required. Once inside, the attacker can perform administrative actions, tamper with device configuration, and chain the bug with the related privilege escalation flaw CVE-2024-9474 for deeper compromise. Only PAN-OS 10.2, 11.0, 11.1 and 11.2 are affected; Cloud NGFW and Prisma Access are not, and risk is greatly reduced when the management interface is restricted to trusted internal IP addresses per vendor best practice. The flaw is being actively exploited: it was added to CISA KEV on 2024-11-18 with known ransomware use, and public reporting describes an ongoing campaign that has compromised more than 2,000 Palo Alto devices using this bug chained with CVE-2024-9474.

Do: Upgrade PAN-OS 10.2, 11.0, 11.1 and 11.2 deployments to the patched releases listed in the vendor advisory (security.paloaltonetworks.com/CVE-2024-0012), ensuring the chained privilege escalation bug CVE-2024-9474 is also addressed. Until patched, never expose the management web interface to untrusted networks or the internet, and restrict access to trusted internal IP addresses only. Review device logs and configurations for signs of compromise (unexpected admin activity or configuration changes) and hunt for persistence on any internet-exposed device.

9.3
group max
100% KEV ransomware PoC
  • Palo Alto Networks PAN-OS PAN-OS 10.2, 11.0, 11.1 and 11.2 (Cloud NGFW and Prisma Access are not impacted)
largetens of thousands of internet-exposed PAN-OS management interfaces, with 2,000+ devices already confirmed compromised
CVE-2025-0108
+1 in the same advisory: …0111
Authentication Bypass in Palo Alto Networks PAN-OS Management Interface

CVE-2025-0108 is a missing-authentication flaw (CWE-306) in the PAN-OS management web interface of Palo Alto Networks firewalls that lets an unauthenticated attacker with network access to that interface bypass login and invoke certain PHP scripts, reportedly via path-confusion tricks in the web server stack. Invoking the scripts does not yield remote code execution, but it can compromise the confidentiality and integrity of PAN-OS, such as by reading or modifying management-plane information. Any PAN-OS firewall whose management web interface is reachable by an attacker — for example, exposed to the internet or reachable from a compromised internal network — is affected, while Cloud NGFW and Prisma Access are not. The flaw is being actively exploited: CISA added it to the Known Exploited Vulnerabilities catalog on 2025-02-18, a public proof-of-concept is available, EPSS puts the 30-day exploitation probability at 98.5%, and headlines report attackers chaining this bug with other PAN-OS flaws to breach firewalls.

Do: Upgrade PAN-OS to a fixed release per the Palo Alto Networks advisory (security.paloaltonetworks.com/CVE-2025-0108), since the vendor has patched the flaw. Until patched, restrict management web interface access to trusted internal IP addresses or management-only network zones as recommended in the vendor's hardening guidance. Check management-interface logs for unauthenticated requests to PHP scripts and for signs of chaining with other recently exploited PAN-OS vulnerabilities.

8.8
group max
98% KEV PoC ×3
  • Palo Alto Networks PAN-OS
large≈ tens of thousands of internet-exposed PAN-OS management interfaces (subset of a much larger firewall install base)
CVE-2025-0109
An unauthenticated file deletion vulnerability in the Palo Alto Networks PAN-OS management web interface enables an unauthenticated attacker with network access

An unauthenticated file deletion vulnerability in the Palo Alto Networks PAN-OS management web interface enables an unauthenticated attacker with network access to the management web interface to delete certain files as the “nobody” user; this includes limited logs and configuration files but does not include system files. You can greatly reduce the risk of this issue by restricting access to the management web interface to only trusted internal IP addresses according to our recommended best practices deployment guidelines https://live.paloaltonetworks.com/t5/community-blogs/tips-amp-tricks-how-to-secure-the-management-access-of-your-palo/ba-p/464431 . This issue does not affect Cloud NGFW or Prisma Access software.

NVD description · AI analysis pending
6.9<1%
Full article523 words · extracted from helpnetsecurity.com · click to collapse

Palo Alto Networks has fixed a high-severity authentication bypass vulnerability (CVE-2025-0108) in the management web interface of its next-gen firewalls, a proof-of-concept exploit (PoC) for which has been made public.

“Palo Alto Networks is not aware of any malicious exploitation of this issue,” the company says.

Fixed PAN-OS vulnerabilities (and unexpected reboots)

CVE-2025-0108 was discovered by Assetnote researchers aftey they decided to analyze the patches for CVE-2024-0012 and CVE-2024-9474, which have been exploited by attackers to compromise over 2,000 PAN firewalls in November 2024.

“As we looked further into the architecture of the management interface, we suspected something was off, even post-patch,” Assetnote researcher Adam Kues explained.

A deeper probe revealed exploitable variations in how three components – Nginx, Apache, and the PHP application – handle web requests to the management interface.

The exploit workflow (Source: Assetnote)

As noted by Assetnote’s CTO Shubham Shah, this vulnerability is a distinct security flaw from the recently patched vulnerabilities, but stems from similar architectural design choices.

After exploiting the flaw, attackers may invoke certain PHP scripts. “While invoking these PHP scripts does not enable remote code execution, it can negatively impact integrity and confidentiality of PAN-OS,” Palo Alto Networks confirmed.

CVE-2025-0108 has been fixed in PAN-OS versions 11.2.4-h4 and later, 11.1.6-h1 and later, 10.2.13-h3 and later, and 10.1.14-h9 and later.

Those updates also contain fixes for CVE-2025-0111, an authenticated file read vulnerability, and CVE-2025-0109, an unauthenticated file deletion vulnerability, both in the firewalls’ management web interface.

Admins are advised to test and implement the updates, but to also prioritize disabling access to the management interface from the internet or any untrusted network and allowing access only from trusted internal IP addresses. This may not be always possible, but taking that step reduces the risk of exploitation of these and other vulnerabilities.

As a sidenote: if some of your PAN firewalls have lately unexpectedly rebooted for no apparent reason, be advised that it’s not due to an attack, but a bug in version 11.1.4-h7/h9 of PAN-OS that is triggered when certain traffic conditions are met.

“The hotfix 11.1.4-h12, which resolves the unexpected reboot issue, was initially shipped with limited availability on January 31. This version was made available to customers requiring immediate resolution, accessible through their account team,” a spokesperson told The Register.

“We are currently validating an additional unrelated regression fix in hotfix 11.1.4-h13. Our goal is to release this as a generally available (GA) update by February 20 or sooner.”

Other PAN fixes

On Wednesday, Palo Alto Networks has also pushed out security updates for:

None of the vulnerabilities fixed in this round of updates is known to have been leveraged by attackers in the wild.

UPDATE (February 13, 2025, 04:35 p.m. ET):

GreyNoise has observed attempts to exploit CVE-2025-0108.

Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats. Subscribe here!

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2025/02/13/pan-os-authentication-bypass-palo-alto-networks-poc-cve-2025-0108/