CVE-2025-0108 is a critical authentication bypass vulnerability in Palo Alto Networks PAN-OS software, affecting the management web interface. An unauthenticated attacker with network access can bypass authentication to invoke certain PHP scripts, potentially impacting the integrity and confidentiality of PAN-OS. This vulnerability has a CVSS score of 9.1 (CRITICAL) due to its network attack vector, low complexity, and high impact on confidentiality and integrity. It is actively exploited in the wild, as confirmed by its inclusion in the KEV catalog and high EPSS score, and has garnered significant community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 10.1.0, < 10.1.14CPE matchmatch criteria | cpe:2.3:o:paloaltonetworks:pan-os:*:*:*:*:*:*:*:* | ||
>= 10.2.0, < 10.2.7CPE matchmatch criteria | cpe:2.3:o:paloaltonetworks:pan-os:*:*:*:*:*:*:*:* | ||
>= 11.1.0, < 11.1.2CPE matchmatch criteria | cpe:2.3:o:paloaltonetworks:pan-os:*:*:*:*:*:*:*:* | ||
>= 11.2.0, < 11.2.4CPE matchmatch criteria | cpe:2.3:o:paloaltonetworks:pan-os:*:*:*:*:*:*:*:* | ||
10.1.14CPE matchmatch criteria | cpe:2.3:o:paloaltonetworks:pan-os:10.1.14:-:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:C/RE:M/U:Red
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.