Missing Authentication for Critical Function in Palo Alto PAN-OS - CVE-2025-0108
Published: February 12, 2025 / Updated: June 20, 2025
Vulnerability details
The vulnerability allows a remote attacker to gain unauthorized access to the system.
The vulnerability exists due to missing authorization in web management interface. A remote non-authenticated attacker can request directly certain PHP scripts to bypass authentication process and gain unauthorized access to the system.
Affected software
How to mitigate CVE-2025-0108
Links to Public Exploits and PoC-codes
- Exploit #11159 - CVE-2025-0108 (February 21, 2025)
- Exploit #11157 - CVE-2025-0108 (February 21, 2025)
- Exploit #11155 - CVE-2025-0108-Authentication-Bypass-checker (February 21, 2025)
- Exploit #11154 - PAN-OS-Authentication-Bypass-Checker-CVE-2025-0108- (February 21, 2025)
- Exploit #11153 - CVE-2025-0108-PoC (February 21, 2025)
- Exploit #11150 - CVE-2025-0108-SCAN (February 21, 2025)