PAN-SA-2025-0003: Informational: PAN-OS BIOS and Bootloader Security Bulletin
Palo Alto Networks is aware of claims of multiple vulnerabilities in hardware device firmware and bootloaders included in our PA-Series (hardware) firewalls.
It is not possible for malicious actors or PAN-OS administrators to exploit these vulnerabilities under normal conditions on PAN-OS versions with up-to-date, secured management interfaces deployed according to the best practices guidelines (https://docs.paloaltonetworks.com/best-practices/10-1/administrative-access-best-practices/administrative-access-best-practices/deploy-administrative-access-best-practices). Users and administrators do not have access to the BIOS firmware or permissions to modify it. An attacker would need to first compromise the system and then get the root Linux privileges necessary to perform these actions before they could exploit these vulnerabilities. These vulnerabilities themselves do not allow an attacker to compromise the PAN-OS software on the firewall.
None of the concerns are applicable to PAN-OS CN-Series, PAN-OS VM-Series, Cloud NGFW and Prisma Access.
Affected Software
Remediation
Mitigation
Information
Event History
Frequently Asked Questions
What is the severity of PAN-SA-2025-0003?
The severity of PAN-SA-2025-0003 has not been explicitly classified but it is advisable to assess potential risks based on your environment.
How do I fix PAN-SA-2025-0003?
To mitigate the vulnerabilities associated with PAN-SA-2025-0003, ensure all affected Palo Alto Networks firmware and software are updated to the latest versions.
Which products are affected by PAN-SA-2025-0003?
PAN-SA-2025-0003 affects various products including Palo Alto Networks Cloud NGFW, PAN-OS CN-Series, PAN-OS PA-Series, PAN-OS VM-Series, and Prisma Access.
Can PAN-SA-2025-0003 be exploited by malicious actors?
Under normal conditions, PAN-SA-2025-0003 cannot be exploited by malicious actors or PAN-OS administrators.
Are there any workarounds for PAN-SA-2025-0003?
Currently, specific workarounds have not been provided for PAN-SA-2025-0003, so keeping systems updated is the recommended approach.