Improper Input Neutralization Vulnerability in Palo Alto Networks PAN-OS Management Interface
CVE-2025-0125

5.8MEDIUM

Key Information:

Vendor
CVE Published:
11 April 2025

Badges

👾 Exploit Exists

Summary

An improper input neutralization flaw in the management web interface of Palo Alto Networks PAN-OS software allows a malicious authenticated read-write administrator to impersonate a legitimate PAN-OS administrator. Exploitation of this vulnerability requires network access to the management interface, emphasizing the importance of restricting access to trusted internal IP addresses to mitigate potential risks. It is noteworthy that this issue does not impact Cloud NGFW or Prisma Access instances.

Affected Version(s)

PAN-OS 11.2.0 < 11.2.5

PAN-OS 11.1.0 < 11.1.5

PAN-OS 11.0.0 < 11.0.6

References

CVSS V4

Score:
5.8
Severity:
MEDIUM
Confidentiality:
High
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

Visa Cybersecurity team
Deloitte Romania, represented by Razvan Ilisanu and Matei “Mal” Badanoiu,
.