CVE-2025-0109: PAN-OS: Unauthenticated File Deletion Vulnerability on the Management Web Interface
An unauthenticated file deletion vulnerability in the Palo Alto Networks PAN-OS management web interface enables an unauthenticated attacker with network access to the management web interface to delete certain files as the “nobody” user; this includes limited logs and configuration files but does not include system files.
The attacker must have network access to the management web interface to exploit this issue. You can greatly reduce the risk of this issue by restricting access to the management web interface to only trusted internal IP addresses according to our recommended critical deployment guidelines (https://live.paloaltonetworks.com/t5/community-blogs/tips-amp-tricks-how-to-secure-the-management-access-of-your-palo/ba-p/464431).
This issue does not affect Cloud NGFW or Prisma Access software.
Other sources
An unauthenticated file deletion vulnerability in the Palo Alto Networks PAN-OS management web interface enables an unauthenticated attacker with network access to the management web interface to delete certain files as the “nobody” user; this includes limited logs and configuration files but does not include system files.
You can greatly reduce the risk of this issue by restricting access to the management web interface to only trusted internal IP addresses according to our recommended best practices deployment guidelines https://live.paloaltonetworks.com/t5/community-blogs/tips-amp-tricks-how-to-secure-the-management-access-of-your-palo/ba-p/464431 .
This issue does not affect Cloud NGFW or Prisma Access software.
— NVD
Affected Software
Remediation
Mitigation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-0109?
CVE-2025-0109 is considered high severity due to its ability to allow unauthenticated attackers to delete files from the PAN-OS management interface.
How do I fix CVE-2025-0109?
To remediate CVE-2025-0109, upgrade to a patched version of PAN-OS such as 10.1.14-h9, 10.2.13-h3, 11.1.6-h1, or 11.2.4-h4.
Who is affected by CVE-2025-0109?
CVE-2025-0109 affects users of Palo Alto Networks PAN-OS and related products like Prisma Access and Cloud NGFW.
What types of files can be deleted due to CVE-2025-0109?
CVE-2025-0109 allows the deletion of certain files, including limited logs and configuration files, by an unauthenticated attacker.
Is user authentication required to exploit CVE-2025-0109?
No, CVE-2025-0109 can be exploited by unauthenticated attackers with network access to the management web interface.