PAN-SA-2025-0003: Informational: PAN-OS BIOS and Bootloader Security Bulletin

Published Jan 23, 2025
·
Updated

Palo Alto Networks is aware of claims of multiple vulnerabilities in hardware device firmware and bootloaders included in our PA-Series (hardware) firewalls.

It is not possible for malicious actors or PAN-OS administrators to exploit these vulnerabilities under normal conditions on PAN-OS versions with up-to-date, secured management interfaces deployed according to the best practices guidelines (https://docs.paloaltonetworks.com/best-practices/10-1/administrative-access-best-practices/administrative-access-best-practices/deploy-administrative-access-best-practices). Users and administrators do not have access to the BIOS firmware or permissions to modify it. An attacker would need to first compromise the system and then get the root Linux privileges necessary to perform these actions before they could exploit these vulnerabilities. These vulnerabilities themselves do not allow an attacker to compromise the PAN-OS software on the firewall.

None of the concerns are applicable to PAN-OS CN-Series, PAN-OS VM-Series, Cloud NGFW and Prisma Access.

Affected Software

2 affected components
Palo Alto Networks Cloud NGFW
Palo Alto Networks Prisma Access

Remediation

Mitigation

These vulnerabilities require an attacker to compromise PAN-OS software before they can successfully exploit it. The risk of exploitation on PAN-OS software is reduced by upgrading your appliances to the latest versions. Additionally secure access to the management web interface by restricting access to only trusted internal IP addresses according to our recommended best practice deployment guidelines (https://docs.paloaltonetworks.com/best-practices).

Information

While the conditions required to exploit these vulnerabilities are not available to users protected by PAN-OS or administrators of PAN-OS software, we are working with the third-party vendors to develop any firmware updates that may be needed. We will provide further updates and guidance as they become available.

Event History

Jan 23, 2025
Advisory Published
via Palo Alto Networks·11:20 PM
Jun 24, 2025
Advisory Published
via Palo Alto Networks·10:00 PM
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of PAN-SA-2025-0003?

The severity of PAN-SA-2025-0003 has not been explicitly classified but it is advisable to assess potential risks based on your environment.

2

How do I fix PAN-SA-2025-0003?

To mitigate the vulnerabilities associated with PAN-SA-2025-0003, ensure all affected Palo Alto Networks firmware and software are updated to the latest versions.

3

Which products are affected by PAN-SA-2025-0003?

PAN-SA-2025-0003 affects various products including Palo Alto Networks Cloud NGFW, PAN-OS CN-Series, PAN-OS PA-Series, PAN-OS VM-Series, and Prisma Access.

4

Can PAN-SA-2025-0003 be exploited by malicious actors?

Under normal conditions, PAN-SA-2025-0003 cannot be exploited by malicious actors or PAN-OS administrators.

5

Are there any workarounds for PAN-SA-2025-0003?

Currently, specific workarounds have not been provided for PAN-SA-2025-0003, so keeping systems updated is the recommended approach.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203