Improper Input Neutralization Vulnerability in Palo Alto Networks PAN-OS Management Interface
CVE-2025-0125
5.8MEDIUM
Summary
An improper input neutralization flaw in the management web interface of Palo Alto Networks PAN-OS software allows a malicious authenticated read-write administrator to impersonate a legitimate PAN-OS administrator. Exploitation of this vulnerability requires network access to the management interface, emphasizing the importance of restricting access to trusted internal IP addresses to mitigate potential risks. It is noteworthy that this issue does not impact Cloud NGFW or Prisma Access instances.
Affected Version(s)
PAN-OS 11.2.0 < 11.2.5
PAN-OS 11.1.0 < 11.1.5
PAN-OS 11.0.0 < 11.0.6
References
CVSS V4
Score:
5.8
Severity:
MEDIUM
Confidentiality:
High
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown
Timeline
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved
Credit
Visa Cybersecurity team
Deloitte Romania, represented by Razvan Ilisanu and Matei “Mal” Badanoiu,