CVE-2025-0111 is an authenticated file read vulnerability in Palo Alto Networks PAN-OS management web interface that allows attackers to read files on the filesystem. This vulnerability is being actively exploited in the wild and is part of CISA's Known Exploited Vulnerabilities catalog.
Data Source: CIRCL
Confidence: HIGH
Exploitation Method: DIRECT_NETWORK
CVE Published: 2025-02-12
Added to CISA KEV: 2025-02-20 8 DAYS BETWEEN CVE AND KEV
CVE-2025-0111 is an authenticated file read vulnerability affecting the management web interface of Palo Alto Networks PAN-OS software [4]. It has been assigned a CVSS score of 7.1 (HIGH) [6].
Despite fixes also being released for CVE-2025-0111 in February 2025, Palo Alto updated a previously distributed advisory after observing threat actors chaining it with CVE-2025-0108 and CVE-2024-9474 in exploit attempts on unpatched and unsecured PAN-OS web management interfaces.
CVE-2025-0111 is an authenticated file read vulnerability that affects the firewall's management interface. The primary risk is when this ...
CVE-2025-0111 allows reading of configuration files, logs, or credential stores that are accessible to the โnobodyโ service account. For example ...
An authenticated file read vulnerability in the management web interface of the Palo Alto Networks PAN-OS software enables an authenticated attacker with ... Learn how an attacker can exploit a file read vulnerability in the management web interface of Palo Alto Networks PAN-OS software to access reโฆ
CVE-2025-0111 is a file read vulnerability in PAN-OS that allows authenticated attackers to read sensitive files. It is being chained with CVE-2025-0108 and CVE-2024-9474, two other flaws that grant root privileges, in active attacks.
An authenticated attacker can read files on the PAN-OS filesystem that are readable by the โnobodyโ user. This issue affects some versions of Palo Alto Networks PAN-OS software and has a CVSS score of 7.1 (HIGH).
An authenticated file read vulnerability in the Palo Alto Networks PAN-OS software enables an authenticated attacker with network access to the management web ...