CVE-2025-0128: PAN-OS: Firewall Denial of Service (DoS) Using a Specially Crafted Packet (Severity: MEDIUM)
A denial-of-service (DoS) vulnerability in the Simple Certificate Enrollment Protocol (SCEP) authentication feature of Palo Alto Networks PAN-OS® software enables an unauthenticated attacker to initiate system reboots using a maliciously crafted packet. Repeated attempts to initiate a reboot causes the firewall to enter maintenance mode.
Cloud NGFW is not affected by this vulnerability. Prisma® Access software is proactively patched and protected from this issue.
Affected Software
Remediation
Mitigation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-0128?
CVE-2025-0128 is classified as a denial-of-service (DoS) vulnerability.
How do I fix CVE-2025-0128?
To fix CVE-2025-0128, you should update your Palo Alto Networks PAN-OS to a version that is not affected by this vulnerability.
Who is affected by CVE-2025-0128?
Any user running affected versions of Palo Alto Networks PAN-OS, including versions up to 11.2.3, may be susceptible to CVE-2025-0128.
What attack vector is used in CVE-2025-0128?
CVE-2025-0128 allows unauthenticated attackers to send malicious packets to trigger system reboots.
What is the overall impact of CVE-2025-0128 on systems?
The overall impact of CVE-2025-0128 can result in system downtime due to repeated unauthorized reboots.