EXPOSURES › CVE-2025-0111
CVE-2025-0111
HIGH ⌖ ON CISA KEV · EXPLOITEDA Palo Alto Networks PAN-OS vulnerability allows authenticated attackers to read arbitrary files on the system, potentially exposing sensitive data and configurations.
CVE-2025-0111 enables authenticated attackers with network access to read files accessible by the 'nobody' user on PAN-OS systems. This poses a significant risk to DIB organizations using Palo Alto Networks firewalls, potentially exposing configuration data, credentials, or other sensitive information, and impacting CMMC compliance. Immediate patching and review of file permissions are required.
Shame score — The vulnerability's ease of exploitation and potential for data exposure, combined with Palo Alto Networks' history of similar issues, demonstrates a concerning lack of diligence.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Palo Alto Networks PAN-OS contains an external control of file name or path vulnerability. Successful exploitation enables an authenticated attacker with network access to the management web interface to read files on the PAN-OS filesystem that are readable by the “nobody” user.
| PRODUCT | STATUS |
|---|---|
| GCS-HIGH Palo Alto Networks, Inc. |
Ready |
| Palo Alto Networks Government Cloud Services Palo Alto Networks, Inc. |
Authorized |