← Vulnerability feed

Vulnerability record · CVE-2025-0111 · published 12 February 2025

CVE-2025-0111: PAN-OS authenticated file read via management web interface

Paloaltonetworks · Pan Os

PAN-OS contains an authenticated file read vulnerability that lets a user with network access to the management web interface read files on the PAN-OS filesystem that are readable by the "nobody" user. The flaw is a path/file access control weakness (CWE-73, CWE-610) and is rated high severity (CVSS 4.0 7.1). It matters because it exposes sensitive local files to any authenticated management user, and CISA added it to the Known Exploited Vulnerabilities catalog.

7.1 CVSS 4.0 High CISA KEV since 20 Feb 2025 EPSS 2.0% · top 20.1% CWE-73 · CWE-73CWE-610 · CWE-610
7.1CVSS 4.0 base score
2.0%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

An authenticated file read vulnerability in the Palo Alto Networks PAN-OS software enables an authenticated attacker with network access to the management web interface to read files on the PAN-OS filesystem that are readable by the “nobody” user. You can greatly reduce the risk of this issue by restricting access to the management web interface to only trusted internal IP addresses according to our recommended best practices deployment guidelines https://live.paloaltonetworks.com/t5/community-blogs/tips-amp-tricks-how-to-secure-the-management-access-of-your-palo/ba-p/464431 . This issue does not affect Cloud NGFW or Prisma Access software.

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

high priorityThe flaw is high severity, requires authentication but no user interaction, and is listed in CISA KEV as exploited, making it a priority for patching and management interface restriction.

What it is

PAN-OS contains an authenticated file read vulnerability that lets a user with network access to the management web interface read files on the PAN-OS filesystem that are readable by the "nobody" user. The flaw is a path/file access control weakness (CWE-73, CWE-610) and is rated high severity (CVSS 4.0 7.1). It matters because it exposes sensitive local files to any authenticated management user, and CISA added it to the Known Exploited Vulnerabilities catalog.

Impact

An attacker with valid credentials and management web interface access can read files on the PAN-OS filesystem accessible to the "nobody" account. This can expose configuration data, credentials, or other sensitive local files, though integrity and availability are not affected.

Attack surface

Reached over the network through the PAN-OS management web interface; the attacker must be authenticated (PR:L) and have network access to that interface. No user interaction is required (UI:N).

Exploitation

CISA added this to the Known Exploited Vulnerabilities catalog on 2025-02-20, indicating known exploitation, while EPSS is low at 0.01999 (79.7th percentile). No ransomware campaign use is documented.

What to do

  • Apply the vendor patch or fixed PAN-OS release per the Palo Alto Networks advisory.
  • Restrict management web interface access to trusted internal IP addresses only.
  • Disable or limit management interface exposure to untrusted networks.
  • Enforce least privilege and review accounts with management web interface access.
  • Monitor for and rotate any credentials or secrets that may have been exposed in readable files.

Detection

  • Review management web interface access logs for unusual or unexpected authenticated sessions.
  • Hunt for requests to management interface endpoints that attempt to read arbitrary filesystem paths.
  • Alert on access to the management interface from IP addresses outside trusted internal ranges.
  • Correlate authentication events with subsequent file access or configuration export activity.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2025-0111 to the Known Exploited Vulnerabilities catalog on 20 February 2025 as "Palo Alto Networks PAN-OS File Read Vulnerability". Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Federal deadline 13 March 2025.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-0111 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2024-3400PAN-OS GlobalProtect command injection allows unauthenticated root code executionA command injection caused by arbitrary file creation in the GlobalProtect feature of Palo Alto Networks PAN-OS lets an unauthenticated attacker run …KEVEPSS 100%analysed10.0CVE-2020-2021PAN-OS SAML signature verification bypass allows authentication bypassPAN-OS fails to properly verify SAML signatures when SAML authentication is enabled and the 'Validate Identity Provider Certificate' option is unchec…KEVEPSS 4.4%analysed9.8CVE-2017-15944PAN-OS management interface input validation flaw allows remote code executionPAN-OS versions before 6.1.19, 7.0.x before 7.0.19, 7.1.x before 7.1.14, and 8.0.x before 8.0.6 contain an input validation and memory buffer overflo…KEVEPSS 98%analysed9.3CVE-2026-0300PAN-OS User-ID Authentication Portal buffer overflow allows root code executionA buffer overflow (out-of-bounds write, CWE-787) in the User-ID Authentication Portal (Captive Portal) service of Palo Alto Networks PAN-OS lets an u…KEVEPSS 32%analysed9.3CVE-2024-0012PAN-OS Management Web Interface Authentication BypassPAN-OS contains a missing authentication flaw (CWE-306) in the management web interface that lets an unauthenticated network attacker obtain PAN-OS a…KEVEPSS 100%analysed8.8CVE-2025-0108PAN-OS management web interface authentication bypassPAN-OS contains a missing-authentication flaw (CWE-306) in the management web interface that lets an unauthenticated attacker with network access inv…KEVEPSS 98%analysed8.7CVE-2024-3393PAN-OS DNS Security packet causes firewall reboot and maintenance modeA denial of service flaw in the DNS Security feature of Palo Alto Networks PAN-OS lets an unauthenticated attacker send a crafted packet through the …KEVEPSS 28%analysed8.6CVE-2022-0028PAN-OS URL filtering misconfiguration enables reflected TCP DoSA PAN-OS URL filtering policy misconfiguration allows a network-based attacker to use PA-Series, VM-Series and CN-Series firewalls to conduct reflect…KEVEPSS 2.4%analysed

Source: NIST National Vulnerability Database (record CVE-2025-0111), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.