Skip to content
COOEY

EXPOSURES › CVE-2025-0111

CVE-2025-0111

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2025-02-20 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2025-0111 ↗
⌖ EXPLOITED IN THE WILD SHAME 72/100 exploited-in-wildunpatched

A Palo Alto Networks PAN-OS vulnerability allows authenticated attackers to read arbitrary files on the system, potentially exposing sensitive data and configurations.

CVE-2025-0111 enables authenticated attackers with network access to read files accessible by the 'nobody' user on PAN-OS systems. This poses a significant risk to DIB organizations using Palo Alto Networks firewalls, potentially exposing configuration data, credentials, or other sensitive information, and impacting CMMC compliance. Immediate patching and review of file permissions are required.

Shame score — The vulnerability's ease of exploitation and potential for data exposure, combined with Palo Alto Networks' history of similar issues, demonstrates a concerning lack of diligence.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Palo Alto Networks PAN-OS contains an external control of file name or path vulnerability. Successful exploitation enables an authenticated attacker with network access to the management web interface to read files on the PAN-OS filesystem that are readable by the “nobody” user.

AFFECTED FEDRAMP PRODUCTS · 2
PRODUCTSTATUS
GCS-HIGH
Palo Alto Networks, Inc.
Ready
Palo Alto Networks Government Cloud Services
Palo Alto Networks, Inc.
Authorized