CVE-2025-0137: PAN-OS: Improper Neutralization of Input in the Management Web Interface
An improper input neutralization vulnerability in the management web interface of the Palo Alto Networks PAN-OS® software enables a malicious authenticated read-write administrator to impersonate another legitimate authenticated PAN-OS administrator.
The attacker must have network access to the management web interface to exploit this issue. You greatly reduce the risk of this issue by restricting access to the management web interface to only trusted internal IP addresses according to our recommended critical deployment guidelines https://live.paloaltonetworks.com/t5/community-blogs/tips-amp-tricks-how-to-secure-the-management-access-of-your-palo/ba-p/464431 .
Other sources
An improper input neutralization vulnerability in the management web interface of the Palo Alto Networks PAN-OS® software enables a malicious authenticated read-write administrator to impersonate another legitimate authenticated PAN-OS administrator.
The attacker must have network access to the management web interface to exploit this issue. You greatly reduce the risk of this issue by restricting access to the management web interface to only trusted internal IP addresses according to our recommended critical deployment guidelines (https://live.paloaltonetworks.com/t5/community-blogs/tips-amp-tricks-how-to-secure-the-management-access-of-your-palo/ba-p/464431).
— Palo Alto Networks
Affected Software
Remediation
Mitigation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-0137?
CVE-2025-0137 is considered a critical vulnerability due to its potential for authenticated administrator impersonation.
How do I fix CVE-2025-0137?
To remediate CVE-2025-0137, upgrade your Palo Alto Networks PAN-OS to versions 11.2.5, 11.1.8, 10.2.13, or 10.1.14-h14 or later.
Who is affected by CVE-2025-0137?
CVE-2025-0137 affects the management web interface of Palo Alto Networks PAN-OS and the Cloud NGFW product.
What type of vulnerability is CVE-2025-0137?
CVE-2025-0137 is classified as an improper input neutralization vulnerability.
What can an attacker do with CVE-2025-0137?
An attacker with this vulnerability can impersonate another legitimate authenticated PAN-OS administrator, potentially leading to unauthorized access.