Attackers are actively exploiting an authentication bypass flaw found in the Palo Alto Networks PAN-OS software that lets an unauthenticated attacker bypass authentication of that interface and invoke certain PHP scripts. Both the Cybersecurity Infrastructure and Security Agency (CISA) and security researchers are warning of increasing attacker activity to exploit the flaw, tracked as CVE-2025-0108 and first revealed in a blog post on Feb. 12 as a zero-day flaw by researchers at Searchlight Cyber AssetNote. PAN-OS is the operating system for Palo Alto's firewall devices; the flaw affects certain versions of PAN-OS v11.2, v11.1 , v10.2, and v10.1 and has been patched for all affected versions. Patch info is available in Palo Alto's security advisory on CVE-2025-0108, which is rated as 8.8 and therefore of high severity on the CVSS. The company warned that while the PHP scripts that can be invoked do not themselves enable remote code execution, exploiting the flaw "can negatively impact integrity and confidentiality of PAN-OS," potentially giving attackers access to vulnerable systems, where other bugs could be used to achieve further aims. Indeed, researchers observed attackers making exploit attempts by chaining CVE-2025-0108 with two other PAN-OS Web management interface flaws — CVE-2024-9474, a privilege escalation flaw, and CVE-2025-0111, an authenticated file read vulnerability — on unpatched and unsecured PAN-OS instances. Threat actors apparently got the memo on the pot...
Patch Now: CISA Warns of Palo Alto Flaw Exploited in the Wild
Dark Reading
·Elizabeth Montalbano
·Published Feb 19, 2025
·Updated
Affected Software
8 affected components
Palo Alto Networks PAN-OS=11.2
Palo Alto Networks PAN-OS=11.1
Palo Alto Networks PAN-OS=10.2
Palo Alto Networks PAN-OS=10.1
Palo Alto Networks PAN-OS=11.2
Palo Alto Networks PAN-OS=11.1
Palo Alto Networks PAN-OS=10.2
Palo Alto Networks PAN-OS=10.1
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses a critical authentication bypass flaw in Palo Alto Networks PAN-OS that is currently being exploited by attackers.
2
What security implications are discussed in the article?
The flaw allows unauthenticated attackers to bypass authentication and invoke certain PHP scripts, posing a significant security risk to systems running affected software.
3
Which versions of PAN-OS are affected by the vulnerability?
The affected versions of Palo Alto Networks PAN-OS include 11.2, 11.1, 10.2, and 10.1.
4
What action does CISA recommend in response to the vulnerability?
CISA recommends that organizations immediately patch their systems to protect against this vulnerability.
5
Why is it urgent to address the Pinto flaw in PAN-OS?
The urgency stems from the ongoing exploitation of the flaw in the wild, making systems that are not patched highly vulnerable to attacks.