Skip to content
COOEY

EXPOSURES › CVE-2025-0108

CVE-2025-0108

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2025-02-18 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2025-0108 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 72/100 exploited-in-wildunpatchedauth-bypassrce

A zero-day authentication bypass vulnerability in Palo Alto Networks PAN-OS allowed unauthenticated attackers network access to invoke PHP scripts, bypassing authentication controls entirely.

This vulnerability, actively exploited in the wild, allows attackers to bypass authentication and execute commands on Palo Alto Networks' PAN-OS devices. DIB organizations using PAN-OS must immediately patch to prevent unauthorized access and potential data compromise, impacting CMMC compliance requirements related to access control.

Shame score — A major cybersecurity vendor's flagship product suffered a critical, actively exploited authentication bypass, demonstrating a systemic failure in security design and testing.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Palo Alto Networks PAN-OS contains an authentication bypass vulnerability in its management web interface. This vulnerability allows an unauthenticated attacker with network access to the management web interface to bypass the authentication normally required and invoke certain PHP scripts.

AFFECTED FEDRAMP PRODUCTS · 2
PRODUCTSTATUS
GCS-HIGH
Palo Alto Networks, Inc.
Ready
Palo Alto Networks Government Cloud Services
Palo Alto Networks, Inc.
Authorized