CVE-2025-0108

CRITICAL KEV NUCLEI LAB

Palo Alto Networks PAN-OS - Auth Bypass

Title source: llm

Description

An authentication bypass in the Palo Alto Networks PAN-OS software enables an unauthenticated attacker with network access to the management web interface to bypass the authentication otherwise required by the PAN-OS management web interface and invoke certain PHP scripts. While invoking these PHP scripts does not enable remote code execution, it can negatively impact integrity and confidentiality of PAN-OS. You can greatly reduce the risk of this issue by restricting access to the management web interface to only trusted internal IP addresses according to our recommended best practices deployment guidelines https://live.paloaltonetworks.com/t5/community-blogs/tips-amp-tricks-how-to-secure-the-management-access-of-your-palo/ba-p/464431 . This issue does not affect Cloud NGFW or Prisma Access software.

Exploits (7)

nomisec WORKING POC 32 stars
by iSee857 · remote
https://github.com/iSee857/CVE-2025-0108-PoC
nomisec SCANNER 8 stars
by FOLKS-iwd · infoleak
https://github.com/FOLKS-iwd/CVE-2025-0108-PoC
nomisec SCANNER 2 stars
by becrevex · infoleak
https://github.com/becrevex/CVE-2025-0108
nomisec SCANNER 2 stars
by fr4nc1stein · infoleak
https://github.com/fr4nc1stein/CVE-2025-0108-SCAN
nomisec SCANNER 1 stars
by sohaibeb · infoleak
https://github.com/sohaibeb/CVE-2025-0108
github WORKING POC
by kso4more · pythonpoc
https://github.com/kso4more/CVE-2025-0108
nomisec SCANNER
by barcrange · infoleak
https://github.com/barcrange/CVE-2025-0108-Authentication-Bypass-checker

Nuclei Templates (1)

PAN-OS Management Interface - Path Confusion to Authentication Bypass
CRITICALVERIFIEDby halencarjunior,ritikchaddha
Shodan: cpe:"cpe:2.3:o:paloaltonetworks:pan-os" || http.favicon.hash:"-631559155"
FOFA: icon_hash="-631559155"

Scores

CVSS v3 9.1
EPSS 0.9412
EPSS Percentile 99.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Details

CISA KEV 2025-02-18
VulnCheck KEV 2025-02-13
ENISA EUVD EUVD-2025-1505
CWE
CWE-306
Status published
Products (3)
paloaltonetworks/pan-os 10.1.14 (9 CPE variants)
paloaltonetworks/pan-os 10.2.7 (24 CPE variants)
paloaltonetworks/pan-os 10.2.8 (17 CPE variants)
Published Feb 12, 2025
KEV Added Feb 18, 2025
Tracked Since Feb 18, 2026