216.73.217.50

CVE-2025-0111

· Published 12/02/2025 21:15 · Modified 21/02/2025 14:50

Labels: CVE-2025-0111 2025-02-12CVE-2025-0111CWE-610CWE-73[email protected]

Essential information

Published
12/02/2025 21:15
Modified
21/02/2025 14:50
Author
Creator
CVSS
6.5 MEDIUM (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

CVSS metrics

Description

An authenticated file read vulnerability in the Palo Alto Networks PAN-OS software enables an authenticated attacker with network access to the management web interface to read files on the PAN-OS filesystem that are readable by the “nobody” user. You can greatly reduce the risk of this issue by restricting access to the management web interface to only trusted internal IP addresses according to our recommended best practices deployment guidelines https://live.paloaltonetworks.com/t5/community-blogs/tips-amp-tricks-how-to-secure-the-management-access-of-your-palo/ba-p/464431 . This issue does not affect Cloud NGFW or Prisma Access software.

NVD status

Status
Analyzed — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
paloaltonetworks / pan-os cpe:2.3:o:paloaltonetworks:pan-os:*:*:*:*:*:*:*:*
paloaltonetworks / pan-os cpe:2.3:o:paloaltonetworks:pan-os:*:*:*:*:*:*:*:*
paloaltonetworks / pan-os cpe:2.3:o:paloaltonetworks:pan-os:*:*:*:*:*:*:*:*
paloaltonetworks / pan-os cpe:2.3:o:paloaltonetworks:pan-os:*:*:*:*:*:*:*:*
paloaltonetworks / pan-os cpe:2.3:o:paloaltonetworks:pan-os:*:*:*:*:*:*:*:*
paloaltonetworks / pan-os cpe:2.3:o:paloaltonetworks:pan-os:10.1.14:-:*:*:*:*:*:*
paloaltonetworks / pan-os cpe:2.3:o:paloaltonetworks:pan-os:10.1.14:h2:*:*:*:*:*:*
paloaltonetworks / pan-os cpe:2.3:o:paloaltonetworks:pan-os:10.1.14:h4:*:*:*:*:*:*
paloaltonetworks / pan-os cpe:2.3:o:paloaltonetworks:pan-os:10.1.14:h6:*:*:*:*:*:*
paloaltonetworks / pan-os cpe:2.3:o:paloaltonetworks:pan-os:10.1.14:h8:*:*:*:*:*:*
paloaltonetworks / pan-os cpe:2.3:o:paloaltonetworks:pan-os:10.2.7:-:*:*:*:*:*:*
paloaltonetworks / pan-os cpe:2.3:o:paloaltonetworks:pan-os:10.2.7:h1:*:*:*:*:*:*
paloaltonetworks / pan-os cpe:2.3:o:paloaltonetworks:pan-os:10.2.7:h12:*:*:*:*:*:*
paloaltonetworks / pan-os cpe:2.3:o:paloaltonetworks:pan-os:10.2.7:h16:*:*:*:*:*:*
paloaltonetworks / pan-os cpe:2.3:o:paloaltonetworks:pan-os:10.2.7:h18:*:*:*:*:*:*
paloaltonetworks / pan-os cpe:2.3:o:paloaltonetworks:pan-os:10.2.7:h19:*:*:*:*:*:*
paloaltonetworks / pan-os cpe:2.3:o:paloaltonetworks:pan-os:10.2.7:h21:*:*:*:*:*:*
paloaltonetworks / pan-os cpe:2.3:o:paloaltonetworks:pan-os:10.2.7:h3:*:*:*:*:*:*
paloaltonetworks / pan-os cpe:2.3:o:paloaltonetworks:pan-os:10.2.7:h6:*:*:*:*:*:*
paloaltonetworks / pan-os cpe:2.3:o:paloaltonetworks:pan-os:10.2.7:h8:*:*:*:*:*:*
paloaltonetworks / pan-os cpe:2.3:o:paloaltonetworks:pan-os:10.2.8:-:*:*:*:*:*:*
paloaltonetworks / pan-os cpe:2.3:o:paloaltonetworks:pan-os:10.2.8:h10:*:*:*:*:*:*
paloaltonetworks / pan-os cpe:2.3:o:paloaltonetworks:pan-os:10.2.8:h13:*:*:*:*:*:*
paloaltonetworks / pan-os cpe:2.3:o:paloaltonetworks:pan-os:10.2.8:h15:*:*:*:*:*:*
paloaltonetworks / pan-os cpe:2.3:o:paloaltonetworks:pan-os:10.2.8:h18:*:*:*:*:*:*
paloaltonetworks / pan-os cpe:2.3:o:paloaltonetworks:pan-os:10.2.8:h19:*:*:*:*:*:*
paloaltonetworks / pan-os cpe:2.3:o:paloaltonetworks:pan-os:10.2.8:h3:*:*:*:*:*:*
paloaltonetworks / pan-os cpe:2.3:o:paloaltonetworks:pan-os:10.2.8:h4:*:*:*:*:*:*
paloaltonetworks / pan-os cpe:2.3:o:paloaltonetworks:pan-os:10.2.9:-:*:*:*:*:*:*
paloaltonetworks / pan-os cpe:2.3:o:paloaltonetworks:pan-os:10.2.9:h1:*:*:*:*:*:*
paloaltonetworks / pan-os cpe:2.3:o:paloaltonetworks:pan-os:10.2.9:h11:*:*:*:*:*:*
paloaltonetworks / pan-os cpe:2.3:o:paloaltonetworks:pan-os:10.2.9:h14:*:*:*:*:*:*
paloaltonetworks / pan-os cpe:2.3:o:paloaltonetworks:pan-os:10.2.9:h16:*:*:*:*:*:*
paloaltonetworks / pan-os cpe:2.3:o:paloaltonetworks:pan-os:10.2.9:h18:*:*:*:*:*:*
paloaltonetworks / pan-os cpe:2.3:o:paloaltonetworks:pan-os:10.2.9:h19:*:*:*:*:*:*
paloaltonetworks / pan-os cpe:2.3:o:paloaltonetworks:pan-os:10.2.9:h9:*:*:*:*:*:*
paloaltonetworks / pan-os cpe:2.3:o:paloaltonetworks:pan-os:10.2.12:-:*:*:*:*:*:*
paloaltonetworks / pan-os cpe:2.3:o:paloaltonetworks:pan-os:10.2.12:h1:*:*:*:*:*:*
paloaltonetworks / pan-os cpe:2.3:o:paloaltonetworks:pan-os:10.2.12:h2:*:*:*:*:*:*
paloaltonetworks / pan-os cpe:2.3:o:paloaltonetworks:pan-os:10.2.12:h3:*:*:*:*:*:*
paloaltonetworks / pan-os cpe:2.3:o:paloaltonetworks:pan-os:10.2.12:h4:*:*:*:*:*:*
paloaltonetworks / pan-os cpe:2.3:o:paloaltonetworks:pan-os:10.2.13:-:*:*:*:*:*:*
paloaltonetworks / pan-os cpe:2.3:o:paloaltonetworks:pan-os:10.2.13:h1:*:*:*:*:*:*
paloaltonetworks / pan-os cpe:2.3:o:paloaltonetworks:pan-os:10.2.13:h2:*:*:*:*:*:*
paloaltonetworks / pan-os cpe:2.3:o:paloaltonetworks:pan-os:11.1.6:-:*:*:*:*:*:*
paloaltonetworks / pan-os cpe:2.3:o:paloaltonetworks:pan-os:11.2.4:-:*:*:*:*:*:*
paloaltonetworks / pan-os cpe:2.3:o:paloaltonetworks:pan-os:11.2.4:h1:*:*:*:*:*:*
paloaltonetworks / pan-os cpe:2.3:o:paloaltonetworks:pan-os:11.2.4:h2:*:*:*:*:*:*

References