CVE-2025-0116: PAN-OS: Firewall Denial of Service (DoS) Using a Specially Crafted LLDP Frame
A Denial of Service (DoS) vulnerability in Palo Alto Networks PAN-OS software causes the firewall to unexpectedly reboot when processing a specially crafted LLDP frame sent by an unauthenticated adjacent attacker. Repeated attempts to initiate this condition causes the firewall to enter maintenance mode.
This issue does not apply to Cloud NGFWs or Prisma Access software.
Affected Software
Remediation
Mitigation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-0116?
CVE-2025-0116 is classified as a high severity Denial of Service (DoS) vulnerability.
What product versions are affected by CVE-2025-0116?
CVE-2025-0116 affects multiple versions of PAN-OS including 11.2.5, 11.1.8, and 10.2.14 among others.
How can I mitigate the effects of CVE-2025-0116?
To mitigate CVE-2025-0116, it's recommended to upgrade to a patched version of PAN-OS.
What type of attack vector does CVE-2025-0116 utilize?
CVE-2025-0116 can be exploited by an unauthenticated adjacent attacker sending specially crafted LLDP frames.
What are the potential impacts of exploiting CVE-2025-0116?
Exploiting CVE-2025-0116 can lead to unexpected reboots of the affected Palo Alto Networks firewall.