← Vulnerability feed

Vulnerability record · CVE-2025-0108 · published 12 February 2025

CVE-2025-0108: PAN-OS management web interface authentication bypass

Paloaltonetworks · Pan Os

PAN-OS contains a missing-authentication flaw (CWE-306) in the management web interface that lets an unauthenticated attacker with network access invoke certain PHP scripts without logging in. It does not lead to remote code execution, but it undermines the confidentiality and integrity of the firewall's management plane.

8.8 CVSS 4.0 High CISA KEV since 18 Feb 2025 EPSS 98% · top 0.1% CWE-306 · Missing authentication for critical function
8.8CVSS 4.0 base score
98%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
8References, 3 tagged exploit
24 Sep 2026Last modified by NVD

Description

An authentication bypass in the Palo Alto Networks PAN-OS software enables an unauthenticated attacker with network access to the management web interface to bypass the authentication otherwise required by the PAN-OS management web interface and invoke certain PHP scripts. While invoking these PHP scripts does not enable remote code execution, it can negatively impact integrity and confidentiality of PAN-OS. You can greatly reduce the risk of this issue by restricting access to the management web interface to only trusted internal IP addresses according to our recommended best practices deployment guidelines https://live.paloaltonetworks.com/t5/community-blogs/tips-amp-tricks-how-to-secure-the-management-access-of-your-palo/ba-p/464431 . This issue does not affect Cloud NGFW or Prisma Access software.

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 16 September 2026. Confidence: high.

critical priorityIt is in CISA KEV with confirmed in-the-wild exploitation, has an EPSS near 0.98, and allows unauthenticated network access to the firewall management plane.

What it is

PAN-OS contains a missing-authentication flaw (CWE-306) in the management web interface that lets an unauthenticated attacker with network access invoke certain PHP scripts without logging in. It does not lead to remote code execution, but it undermines the confidentiality and integrity of the firewall's management plane.

Impact

An attacker gains unauthenticated access to management web interface functionality, allowing them to read and alter data exposed by the affected PHP scripts. No code execution is achieved, but the management plane's integrity and confidentiality are compromised.

Attack surface

Reachable over the network via the PAN-OS management web interface; the CVSS 4.0 vector shows PR:N and UI:N, so no authentication or user interaction is required. Exposure is limited to interfaces where the management web UI is reachable, which the vendor advises restricting to trusted internal IPs.

Exploitation

CISA added it to KEV on 2025-02-18 with a 2025-03-11 remediation due, and multiple references are tagged Exploit, indicating active exploitation in the wild. EPSS is 0.98455 (99.9th percentile), consistent with high near-term exploitation likelihood.

What to do

  • Apply the vendor patch for PAN-OS per the Palo Alto Networks advisory.
  • Restrict management web interface access to trusted internal IP addresses only.
  • Isolate the management interface from untrusted networks and the public internet.
  • If patching is not immediately possible, follow vendor mitigations or discontinue use of the product as directed by CISA.
  • Review management interface exposure and firewall rules for any internet-facing management access.

Detection

  • Monitor management web interface logs for requests to PHP scripts that occur without a preceding successful authentication.
  • Alert on anomalous or unexpected access to the PAN-OS management web interface from untrusted or external source IPs.
  • Hunt for exploitation attempts using the public PoC and vendor advisory indicators against management interface access logs.
  • Correlate management interface access with configuration or data changes that lack a corresponding authenticated session.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2025-0108 to the Known Exploited Vulnerabilities catalog on 18 February 2025 as "Palo Alto Networks PAN-OS Authentication Bypass Vulnerability". Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Federal deadline 11 March 2025.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-0108 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2024-3400PAN-OS GlobalProtect command injection allows unauthenticated root code executionA command injection caused by arbitrary file creation in the GlobalProtect feature of Palo Alto Networks PAN-OS lets an unauthenticated attacker run …KEVEPSS 100%analysed10.0CVE-2020-2021PAN-OS SAML signature verification bypass allows authentication bypassPAN-OS fails to properly verify SAML signatures when SAML authentication is enabled and the 'Validate Identity Provider Certificate' option is unchec…KEVEPSS 4.4%analysed9.8CVE-2017-15944PAN-OS management interface input validation flaw allows remote code executionPAN-OS versions before 6.1.19, 7.0.x before 7.0.19, 7.1.x before 7.1.14, and 8.0.x before 8.0.6 contain an input validation and memory buffer overflo…KEVEPSS 98%analysed9.3CVE-2026-0300PAN-OS User-ID Authentication Portal buffer overflow allows root code executionA buffer overflow (out-of-bounds write, CWE-787) in the User-ID Authentication Portal (Captive Portal) service of Palo Alto Networks PAN-OS lets an u…KEVEPSS 32%analysed9.3CVE-2024-0012PAN-OS Management Web Interface Authentication BypassPAN-OS contains a missing authentication flaw (CWE-306) in the management web interface that lets an unauthenticated network attacker obtain PAN-OS a…KEVEPSS 100%analysed8.7CVE-2024-3393PAN-OS DNS Security packet causes firewall reboot and maintenance modeA denial of service flaw in the DNS Security feature of Palo Alto Networks PAN-OS lets an unauthenticated attacker send a crafted packet through the …KEVEPSS 28%analysed8.6CVE-2022-0028PAN-OS URL filtering misconfiguration enables reflected TCP DoSA PAN-OS URL filtering policy misconfiguration allows a network-based attacker to use PA-Series, VM-Series and CN-Series firewalls to conduct reflect…KEVEPSS 2.4%analysed8.1CVE-2019-1579PAN-OS GlobalProtect pre-auth remote code executionPAN-OS versions 7.1.18, 8.0.11-h1 and 8.1.2 and earlier contain a remote code execution flaw (CWE-134, format string) that is reachable when the Glob…KEVEPSS 46%analysed

Source: NIST National Vulnerability Database (record CVE-2025-0108), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.