Unauthenticated File Deletion Vulnerability in Palo Alto Networks PAN-OS Management Interface
CVE-2025-0109
Key Information:
- Vendor
Palo Alto Networks
- Vendor
- CVE Published:
- 12 February 2025
Badges
What is CVE-2025-0109?
A vulnerability exists in the management web interface of Palo Alto Networks' PAN-OS that allows an unauthenticated attacker with network access to delete specific files, including certain logs and configuration files, operating as the 'nobody' user. While system files remain unaffected, this issue poses a risk to the integrity of log maintenance and configuration management. To mitigate this risk, it is crucial to restrict access to the management web interface to only trusted internal IP addresses, aligning with best practice guidelines outlined by Palo Alto Networks. This vulnerability does not impact Cloud NGFW or Prisma Access software.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
PAN-OS 10.1.0 < 10.1.14-h9
PAN-OS 10.2.0 < 10.2.7-h24
PAN-OS 11.1.0 < 11.1.6-h1
References
CVSS V4
Timeline
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved