boxscore/security
CVE · referencelatest edition

Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CVE-2025-0111

Palo Alto Networks Cloud NGFW — PAN-OS: Authenticated File Read Vulnerability in the Management Web Interface
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   N   N    7.1   .0200   80.0   YES
AFFECTED
  Product        Versions     Fixed
  Cloud NGFW     unspecified  All
  PAN-OS         10.1.0 –     10.1.14-h9
  Prisma Access  unspecified  All
TIMELINE
  Dec 20  Reserved by palo_alto
  Feb 12  Published (CNA: palo_alto)
  Feb 20  Added to CISA KEV, remediation due 2025-03-13
CWE-73 · CNA: palo_alto · CVSS v4.0 · 2 references · KEV due March 13, 2025

Description

An authenticated file read vulnerability in the Palo Alto Networks PAN-OS software enables an authenticated attacker with network access to the management web interface to read files on the PAN-OS filesystem that are readable by the “nobody” user. You can greatly reduce the risk of this issue by restricting access to the management web interface to only trusted internal IP addresses according to our recommended best practices deployment guidelines https://live.paloaltonetworks.com/t5/community-blogs/tips-amp-tricks-how-to-secure-the-management-access-of-your-palo/ba-p/464431 . This issue does not affect Cloud NGFW or Prisma Access software.

Lifecycle

Complete event history — 3 events, chronological
DateEventDetail
December 20, 2024ReservedReserved by palo_alto
February 12, 2025PublishedPublished (CNA: palo_alto)
February 20, 2025KEV ADDEDAdded to CISA KEV, remediation due 2025-03-13

Affected

Affected products and packages — 3 rows
VendorProduct / PackageEcosystemVersion introducedFixed
Palo Alto NetworksCloud NGFW——All
Palo Alto NetworksPAN-OS—10.1.010.1.14-h9
Palo Alto NetworksPrisma Access——All

Weaknesses

CWE-73

References (2)

Related

Authoritative record: CVE-2025-0111 at cve.org

Vendors: palo alto networks

Weaknesses: CWE-73

About this page

This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2025-0111 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Sunday, October 4, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.