← Back to CVE List
Vulnerability Intelligence Report
PAN-OS: Authenticated File Read Vulnerability in the Management Web Interface

CVE-2025-0111

An authenticated file read vulnerability in the Palo Alto Networks PAN-OS software enables an authenticated attacker with network access to the management web interface to read files on the PAN-OS filesystem that are readable by the “nobody” user. You can greatly reduce the risk of this issue by restricting access to the management web interface to only trusted internal IP addresses according to our recommended best practices deployment guidelines https://live.paloaltonetworks.com/t5/community-blogs/tips-amp-tricks-how-to-secure-the-management-access-of-your-palo/ba-p/464431 . This issue does not affect Cloud NGFW or Prisma Access software.

CISA KEV SSVC: Active Exploitation
CVSS Base Score
7.1
HIGH
EPSS Probability:1.86%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
Authentication
Weaponization
SSVC Action

Weaknesses (CWE)

CWE-73 ↗CWE-73: External Control of File Name or Path

Affected Products & Versions

Vendor Product Affected Versions
Palo Alto Networks Cloud NGFW All (unaffected)
Palo Alto Networks PAN-OS 10.1.0 < 10.1.14-h9 (affected), 10.2.0 < 10.2.7-h24 (affected), 11.1.0 < 11.1.6-h1 (affected), 11.2.0 < 11.2.4-h4 (affected)
Palo Alto Networks Prisma Access All (unaffected)

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

CISA KEV
ACTIVE IN CATALOG
EPSS Score
1.862%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityPalo Alto Networks, Inc. · Vendor · USA
Reserved2024-12-20T23:23:13
Published2025-02-12T20:58:43
Patch Date2025-02-12
Last Updated2026-02-26T19:08:49

LINK COPIED TO CLIPBOARD