๐Ÿ”ด CVE-2025-0111

CVE-2025-0111 is an authenticated file read vulnerability in Palo Alto Networks PAN-OS management web interface that allows attackers to read files on the filesystem. This vulnerability is being actively exploited in the wild and is part of CISA's Known Exploited Vulnerabilities catalog.

โ† Back to Overview
HIGH_RISK
Risk Level
7.1
CVSS Score
NETWORK
Attack Vector
Initial Access
ATT&CK Tactic
T1190 โ€” Exploit Public-Facing Application
ATT&CK Technique
VERY_HIGH
Deployment Risk
No
Ransomware

๐Ÿ“‹ Vulnerability Details

Data Source: CIRCL

Confidence: HIGH

Exploitation Method: DIRECT_NETWORK

CVE Published: 2025-02-12

Added to CISA KEV: 2025-02-20 8 DAYS BETWEEN CVE AND KEV

๐ŸŽฏ Recommendations:

๐Ÿ” Web Intelligence (Kagi ยท 2026-06-04)

CVE-2025-0111 is an authenticated file read vulnerability affecting the management web interface of Palo Alto Networks PAN-OS software [4]. It has been assigned a CVSS score of 7.1 (HIGH) [6].

Active Exploitation and Threat Actor Usage
  • Active Exploitation: The vulnerability has been observed being exploited in the wild [5].
  • Exploit Chaining: Threat actors have been observed chaining CVE-2025-0111 with other vulnerabilities, specifically CVE-2025-0108 and CVE-2024-9474, to conduct attacks against unpatched and unsecured PAN-OS web management interfaces [1]. This chain is used to escalate privileges, as the other vulnerabilities in the chain can grant root access [5].
Attack Method and Requirements
  • Access Requirements: The attacker must have network access to the management web interface [7].
  • Authentication: The vulnerability requires the attacker to be authenticated to the management interface [4].
  • Method: Successful exploitation allows an attacker to read files on the PAN-OS filesystem that are readable by the "nobody" user [6].
Impact and Access
  • Impact: Exploitation provides unauthorized access to sensitive information stored on the system [3].
  • Data Accessible: Attackers can potentially read configuration files, logs, or credential stores that are accessible to the "nobody" service account [3].
Patch and Mitigation Status
  • Status: Palo Alto Networks released fixes for this vulnerability in February 2025 [1].
  • Mitigation: Administrators are advised to ensure their PAN-OS software is updated to the patched versions. Additionally, restricting access to the management web interface to trusted internal networks is a recommended security practice to reduce exposure [2].

Sources

  1. Palo Alto PAN-OS Firewall Flaw CVE-2025-0111 Used in Exploit Chaining ...

    Despite fixes also being released for CVE-2025-0111 in February 2025, Palo Alto updated a previously distributed advisory after observing threat actors chaining it with CVE-2025-0108 and CVE-2024-9474 in exploit attempts on unpatched and unsecured PAN-OS web management interfaces.

  2. reduce exposure to PAN-OS vulnerabilities like CVE-2025-0111

    CVE-2025-0111 is an authenticated file read vulnerability that affects the firewall's management interface. The primary risk is when this ...

  3. Breaking Down Palo Alto Networks PAN-OS Vulnerability - Armis

    CVE-2025-0111 allows reading of configuration files, logs, or credential stores that are accessible to the โ€œnobodyโ€ service account. For example ...

  4. CVE-2025-0111 PAN-OS: Authenticated File Read Vulnerability in ...

    An authenticated file read vulnerability in the management web interface of the Palo Alto Networks PAN-OS software enables an authenticated attacker with ... Learn how an attacker can exploit a file read vulnerability in the management web interface of Palo Alto Networks PAN-OS software to access reโ€ฆ

  5. Palo Alto Networks tags new firewall bug as exploited in attacks

    CVE-2025-0111 is a file read vulnerability in PAN-OS that allows authenticated attackers to read sensitive files. It is being chained with CVE-2025-0108 and CVE-2024-9474, two other flaws that grant root privileges, in active attacks.

  6. NVD - CVE-2025-0111

    An authenticated attacker can read files on the PAN-OS filesystem that are readable by the โ€œnobodyโ€ user. This issue affects some versions of Palo Alto Networks PAN-OS software and has a CVSS score of 7.1 (HIGH).

  7. CVE-2025-0111 Detail - NVD

    An authenticated file read vulnerability in the Palo Alto Networks PAN-OS software enables an authenticated attacker with network access to the management web ...