#VU103926 Missing Authentication for Critical Function in Palo Alto PAN-OS - CVE-2025-0108
Published: February 12, 2025 / Updated: June 20, 2025
Palo Alto PAN-OS
Palo Alto Networks, Inc.
Description
The vulnerability allows a remote attacker to gain unauthorized access to the system.
The vulnerability exists due to missing authorization in web management interface. A remote non-authenticated attacker can request directly certain PHP scripts to bypass authentication process and gain unauthorized access to the system.