Improper Check for Unusual or Exceptional Conditions in Palo Alto PAN-OS and Prisma Access - CVE-2025-0128
Published: April 14, 2025 / Updated: April 16, 2025
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to improper error handling in the Simple Certificate Enrollment Protocol (SCEP) authentication feature. A remote attacker can send specially crafted data to the application and perform a denial of service (DoS) attack.
Affected software
Prisma Access
How to mitigate CVE-2025-0128
Prisma Access - addressed in versions 10.2.4-h36, 10.2.10-h16, 11.2.4-h5