CVE-2025-0137

PAN-OS: Improper Neutralization of Input in the Management Web Interface

Severity
Medium 4.8
CVSS 4.0
Exploited
Not listed
EPSS
0.004
30.3th percentile
Discovered by
Third party
Published by the vendor
Published
May 14, 2025
Assigned by palo_alto

Description

An improper input neutralization vulnerability in the management web interface of the Palo Alto Networks PAN-OS® software enables a malicious authenticated read-write administrator to impersonate another legitimate authenticated PAN-OS administrator. The attacker must have network access to the management web interface to exploit this issue. You greatly reduce the risk of this issue by restricting access to the management web interface to only trusted internal IP addresses according to our recommended critical deployment guidelines https://live.paloaltonetworks.com/t5/community-blogs/tips-amp-tricks-how-to-secure-the-management-access-of-your-palo/ba-p/464431 .

Weakness: CWE-83

Affected products

Vendor Product Category Matched by
Palo Alto Networks Cloud NGFW Firewall / NGFW cna-assigner
Palo Alto Networks PAN-OS Firewall / NGFW cna-assigner
Vendor-reported affected versions (2)
  • Palo Alto Networks · Cloud NGFW
  • Palo Alto Networks · PAN-OS

Credit

Jasper Westerman, Harm Blankers and Yanick de Pater of REQON B.V.

Vendor remediation

Version Minor Version Suggested Solution PAN-OS 11.2 11.2.0 through 11.2.4Upgrade to 11.2.5 or later PAN-OS 11.111.1.0 through 11.1.7 Upgrade to 11.1.8 or laterPAN-OS 10.2 10.2.0 through 10.2.12Upgrade to 10.2.13 or laterPAN-OS 10.1 10.1.0 through 10.1.14 Upgrade to 10.1.14-h14 or later All other unsupported PAN-OS versions Upgrade to a supported fixed version.