File Reading Vulnerability in Palo Alto Networks PAN-OS Software
CVE-2025-0115
6.8MEDIUM
Summary
A vulnerability exists in Palo Alto Networks PAN-OS software, allowing an authenticated administrator on the PAN-OS command-line interface (CLI) to read arbitrary files. This flaw poses a potential risk to sensitive data and system integrity, particularly in configurations where access controls are not strictly enforced. Importantly, this issue does not extend to Cloud NGFW or Prisma Access deployments. Administrators are urged to review their permissions and monitor system usage to mitigate any potential impacts.
Affected Version(s)
PAN-OS 11.2.0 < 11.2.3
PAN-OS 11.1.0 < 11.1.5
PAN-OS 11.0.0 < 11.0.6
References
CVSS V4
Score:
6.8
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved
Credit
Visa Cybersecurity team
Deloitte Romania Cybersecurity team