Hackers are launching attacks against Palo Alto Networks PAN-OS firewalls by exploiting a recently fixed vulnerability (CVE-2025-0108) that allows bypassing authentication. The security issue received a high-severity score and impacts the PAN-OS management web interface and allows an unauthenticated attacker on the network to bypass authentication and invoke certain PHP scripts, potentially compromising integrity and confidentiality. In a security bulletin on February 12, Palo Alto Networks urges admins to upgrade firewalls to the versions below to address the issue: PAN-OS 11.0 is also impacted but the product reached the end of life (EoL) and Palo Alto Networks does not plan to release any fixes for it. Because of this, users are strongly recommended to upgrade to a supported release instead. The vulnerability was discovered and reported to Palo Alto Networks by security researchers at Assetnote. They also published a write-up with complete exploitation details when the patch was released. The researchers demonstrated how the flaw could be leveraged to extract sensitive system data, retrieve firewall configurations, or potentially manipulate certain settings within PAN-OS. The exploit leverages a path confusion between Nginx and Apache in PAN-OS that allows bypassing authentication. Attackers with network access to the management interface can leverage this to gather intelligence for further attacks or to weaken security defenses by modifying accessible settings. Threat mo...
Hackers exploit authentication bypass in Palo Alto Networks PAN-OS
BleepingComputer
·Bill Toulas
·Published Feb 14, 2025
·Updated
Affected Software
2 affected components
Palo Alto Networks PAN-OS=11.0
Palo Alto Networks PAN-OS=11.0
Frequently Asked Questions
1
What vulnerability is being exploited in Palo Alto Networks PAN-OS?
Hackers are exploiting an authentication bypass vulnerability identified as CVE-2025-0108 in Palo Alto Networks PAN-OS.
2
What is the severity rating of the vulnerability in PAN-OS?
The vulnerability in PAN-OS has received a high-severity score, indicating significant security risks.
3
Which version of PAN-OS is affected by this security flaw?
The affected version of PAN-OS being attacked is 11.0.
4
What actions can organizations take to mitigate the risks associated with this vulnerability?
Organizations should apply the security patches provided by Palo Alto Networks to fix the authentication bypass vulnerability.
5
Are there any specific attacks that hackers are launching against PAN-OS?
Hackers are launching attacks that exploit the authentication bypass flaw to gain unauthorized access to PAN-OS firewalls.