CVE-2025-0137
PAN-OS: Improper Neutralization of Input in the Management Web Interface
Description
An improper input neutralization vulnerability in the management web interface of the Palo Alto Networks PAN-OS® software enables a malicious authenticated read-write administrator to impersonate another legitimate authenticated PAN-OS administrator. The attacker must have network access to the management web interface to exploit this issue. You greatly reduce the risk of this issue by restricting access to the management web interface to only trusted internal IP addresses according to our recommended critical deployment guidelines https://live.paloaltonetworks.com/t5/community-blogs/tips-amp-tricks-how-to-secure-the-management-access-of-your-palo/ba-p/464431 .
Weakness: CWE-83
Affected products
| Vendor | Product | Category | Matched by |
|---|---|---|---|
| Palo Alto Networks | Cloud NGFW | Firewall / NGFW | cna-assigner |
| Palo Alto Networks | PAN-OS | Firewall / NGFW | cna-assigner |
Vendor-reported affected versions (2)
- Palo Alto Networks · Cloud NGFW
- Palo Alto Networks · PAN-OS
Credit
Jasper Westerman, Harm Blankers and Yanick de Pater of REQON B.V.
Vendor remediation
Version Minor Version Suggested Solution PAN-OS 11.2 11.2.0 through 11.2.4Upgrade to 11.2.5 or later PAN-OS 11.111.1.0 through 11.1.7 Upgrade to 11.1.8 or laterPAN-OS 10.2 10.2.0 through 10.2.12Upgrade to 10.2.13 or laterPAN-OS 10.1 10.1.0 through 10.1.14 Upgrade to 10.1.14-h14 or later All other unsupported PAN-OS versions Upgrade to a supported fixed version.