216.73.216.233

CVE-2025-0107

· Published 11/01/2025 03:15 · Modified 15/01/2025 23:15

Labels: CVE-2025-0107 2025-01-11CVE-2025-0107CWE-78[email protected]

Essential information

Published
11/01/2025 03:15
Modified
15/01/2025 23:15
Author
Creator
CVSS
7.7 HIGH (v3) 7.7 HIGH (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

An OS command injection vulnerability in Palo Alto Networks Expedition enables an unauthenticated attacker to run arbitrary OS commands as the www-data user in Expedition, which results in the disclosure of usernames, cleartext passwords, device configurations, and device API keys for firewalls running PAN-OS software.

NVD status

Status
Awaiting Analysis — CVE has been marked for Analysis. Normally once in this state the CVE will be analyzed by NVD staff within 24 hours.
Source
[email protected]
NVD
View on NVD

References