boxscore/security
CVE · referencelatest edition

Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CVE-2025-0108

Palo Alto Networks Cloud NGFW — PAN-OS: Authentication Bypass in the Management Web Interface
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   L   N    8.8   .9846   99.9   YES
AFFECTED
  Product        Versions     Fixed
  Cloud NGFW     unspecified  All
  PAN-OS         10.1.0 –     10.1.14-h9
  Prisma Access  unspecified  All
TIMELINE
  Dec 20  Reserved by palo_alto
  Feb 12  Published (CNA: palo_alto)
  Feb 18  Added to CISA KEV, remediation due 2025-03-11
  Sep 24  EXPLOIT PUBLISHED — CVE-2025-0108 (Palo Alto Networks Cloud NGFW). Public exploit reference added.
CWE-306 · CNA: palo_alto · CVSS v4.0 · 8 references · NVD status: Analyzed · KEV due March 11, 2025

Description

An authentication bypass in the Palo Alto Networks PAN-OS software enables an unauthenticated attacker with network access to the management web interface to bypass the authentication otherwise required by the PAN-OS management web interface and invoke certain PHP scripts. While invoking these PHP scripts does not enable remote code execution, it can negatively impact integrity and confidentiality of PAN-OS. You can greatly reduce the risk of this issue by restricting access to the management web interface to only trusted internal IP addresses according to our recommended best practices deployment guidelines https://live.paloaltonetworks.com/t5/community-blogs/tips-amp-tricks-how-to-secure-the-management-access-of-your-palo/ba-p/464431 . This issue does not affect Cloud NGFW or Prisma Access software.

Lifecycle

Complete event history — 4 events, chronological
DateEventDetail
December 20, 2024ReservedReserved by palo_alto
February 12, 2025PublishedPublished (CNA: palo_alto)
February 18, 2025KEV ADDEDAdded to CISA KEV, remediation due 2025-03-11
September 24, 2026EXPLOIT PUBLISHEDEXPLOIT PUBLISHED — CVE-2025-0108 (Palo Alto Networks Cloud NGFW). Public exploit reference added.

Affected

Affected products and packages — 3 rows
VendorProduct / PackageEcosystemVersion introducedFixed
Palo Alto NetworksCloud NGFW——All
Palo Alto NetworksPAN-OS—10.1.010.1.14-h9
Palo Alto NetworksPrisma Access——All

Weaknesses

CWE-306

References (8)

Related

Authoritative record: CVE-2025-0108 at cve.org

Vendors: palo alto networks

Weaknesses: CWE-306

About this page

This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2025-0108 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Sunday, October 4, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.