CVE-2025-0111Palo Alto Networks PAN-OS File Read Vulnerability

PUBLISHEDvulnerability record
2025-02-20 · last modified June 21, 2025

Metadata

CVE ID:
CVE-2025-0111
Project:
Palo Alto Networks
Product:
PAN-OS
Date Added:
2025-02-20
Due Date:
2025-03-13
Last Updated:
June 21, 2025

Vulnerability Name

Palo Alto Networks PAN-OS File Read Vulnerability

Description

Palo Alto Networks PAN-OS contains an external control of file name or path vulnerability. Successful exploitation enables an authenticated attacker with network access to the management web interface to read files on the PAN-OS filesystem that are readable by the “nobody” user.

Known To Be Used in Ransomware Campaigns?

Ransomware Status:
Unknown

Action

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Additional Notes

Related News Articles

Related Weaknesses