• News/
  • https://www.bleepingcomputer.com/news/security/hackers-exploit-authentication-bypass-in-palo-alto-networks-pan-os/

Hackers exploit authentication bypass in Palo Alto Networks PAN-OS

BleepingComputer
·
Bill Toulas
·
Published Feb 14, 2025
·
Updated

Hackers are launching attacks against Palo Alto Networks PAN-OS firewalls by exploiting a recently fixed vulnerability (CVE-2025-0108) that allows bypassing authentication. The security issue received a high-severity score and impacts the PAN-OS management web interface and allows an unauthenticated attacker on the network to bypass authentication and invoke certain PHP scripts, potentially compromising integrity and confidentiality. In a security bulletin on February 12, Palo Alto Networks urges admins to upgrade firewalls to the versions below to address the issue: PAN-OS 11.0 is also impacted but the product reached the end of life (EoL) and Palo Alto Networks does not plan to release any fixes for it. Because of this, users are strongly recommended to upgrade to a supported release instead. The vulnerability was discovered and reported to Palo Alto Networks by security researchers at Assetnote. They also published a write-up with complete exploitation details when the patch was released. The researchers demonstrated how the flaw could be leveraged to extract sensitive system data, retrieve firewall configurations, or potentially manipulate certain settings within PAN-OS. The exploit leverages a path confusion between Nginx and Apache in PAN-OS that allows bypassing authentication. Attackers with network access to the management interface can leverage this to gather intelligence for further attacks or to weaken security defenses by modifying accessible settings. Threat mo...

Read full article

Affected Software

2 affected components
Palo Alto Networks PAN-OS=11.0
Palo Alto Networks PAN-OS=11.0
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What vulnerability is being exploited in Palo Alto Networks PAN-OS?

Hackers are exploiting an authentication bypass vulnerability identified as CVE-2025-0108 in Palo Alto Networks PAN-OS.

2

What is the severity rating of the vulnerability in PAN-OS?

The vulnerability in PAN-OS has received a high-severity score, indicating significant security risks.

3

Which version of PAN-OS is affected by this security flaw?

The affected version of PAN-OS being attacked is 11.0.

4

What actions can organizations take to mitigate the risks associated with this vulnerability?

Organizations should apply the security patches provided by Palo Alto Networks to fix the authentication bypass vulnerability.

5

Are there any specific attacks that hackers are launching against PAN-OS?

Hackers are launching attacks that exploit the authentication bypass flaw to gain unauthorized access to PAN-OS firewalls.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203