Attackers are actively exploiting an authentication bypass flaw found in the Palo Alto Networks PAN-OS software that lets an unauthenticated attacker bypass authentication of that interface and invoke certain PHP scripts. Both the Cybersecurity Infrastructure and Security Agency (CISA) and security researchers are warning of increasing attacker activity to exploit the flaw, tracked as CVE-2025-0108 and first revealed in a blog post on Feb. 12 as a zero-day flaw by researchers at Searchlight Cyber AssetNote. PAN-OS is the operating system for Palo Alto's firewall devices; the flaw affects certain versions of PAN-OS v11.2, v11.1 , v10.2, and v10.1 and has been patched for all affected versions. Patch info is available in Palo Alto's security advisory on CVE-2025-0108, which is rated as 8.8 and therefore of high severity on the CVSS. The company warned that while the PHP scripts that can be invoked do not themselves enable remote code execution, exploiting the flaw "can negatively impact integrity and confidentiality of PAN-OS," potentially giving attackers access to vulnerable systems, where other bugs could be used to achieve further aims. Indeed, researchers observed attackers making exploit attempts by chaining CVE-2025-0108 with two other PAN-OS Web management interface flaws — CVE-2024-9474, a privilege escalation flaw, and CVE-2025-0111, an authenticated file read vulnerability — on unpatched and unsecured PAN-OS instances. Threat actors apparently got the memo on the pot...
Patch Now: Palo Alto Flaw Exploited in the Wild
Dark Reading
·Published Feb 19, 2025
·Updated
Affected Software
4 affected components
Palo Alto Networks PAN-OS=v11.2
Palo Alto Networks PAN-OS=v11.1
Palo Alto Networks PAN-OS=v10.2
Palo Alto Networks PAN-OS=v10.1
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses an actively exploited authentication bypass vulnerability in Palo Alto Networks PAN-OS software.
2
What security implications are discussed in the article?
The security implications include the risk of unauthenticated attackers bypassing authentication and executing PHP scripts.
3
What products or software are affected by this vulnerability?
The vulnerability affects Palo Alto Networks PAN-OS software.
4
Which organization has issued warnings regarding this flaw?
The Cybersecurity Infrastructure and Security Agency (CISA) has issued warnings about this flaw.
5
What action is recommended for users of affected software?
Users of affected software are urged to patch their systems immediately to protect against exploitation.