CVE-2025-0124: PAN-OS: Authenticated File Deletion Vulnerability on the Management Web Interface (Severity: LOW)
An authenticated file deletion vulnerability in the Palo Alto Networks PAN-OS® software enables an authenticated attacker with network access to the management web interface to delete certain files as the “nobody” user; this includes limited logs and configuration files but does not include system files.
The attacker must have network access to the management web interface to exploit this issue. You greatly reduce the risk of this issue by restricting access to the management web interface to only trusted internal IP addresses according to our recommended critical deployment guidelines https://live.paloaltonetworks.com/t5/community-blogs/tips-amp-tricks-how-to-secure-the-management-access-of-your-palo/ba-p/464431 .
This issue affects Cloud NGFW. However, this issue does not affect Prisma® Access software.
Other sources
An authenticated file deletion vulnerability in the Palo Alto Networks PAN-OS® software enables an authenticated attacker with network access to the management web interface to delete certain files as the “nobody” user; this includes limited logs and configuration files but does not include system files.
The attacker must have network access to the management web interface to exploit this issue. You greatly reduce the risk of this issue by restricting access to the management web interface to only trusted internal IP addresses according to our recommended critical deployment guidelines (https://live.paloaltonetworks.com/t5/community-blogs/tips-amp-tricks-how-to-secure-the-management-access-of-your-palo/ba-p/464431).
This issue affects Cloud NGFW. However, this issue does not affect Prisma® Access software.
— Palo Alto Networks
Affected Software
Remediation
Mitigation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-0124?
CVE-2025-0124 is rated as a medium severity vulnerability affecting certain Palo Alto Networks products.
How do I fix CVE-2025-0124?
To remediate CVE-2025-0124, upgrade to the fixed versions of PAN-OS provided by Palo Alto Networks.
What products are affected by CVE-2025-0124?
CVE-2025-0124 affects Palo Alto Networks PAN-OS, Cloud NGFW, and Prisma Access products.
Can unauthenticated users exploit CVE-2025-0124?
No, only authenticated users with network access to the management web interface can exploit CVE-2025-0124.
What types of files can be deleted due to CVE-2025-0124?
CVE-2025-0124 allows the deletion of specific logs and configuration files as the 'nobody' user.