A critical security vulnerability (CVE-2025-0108) in Palo Alto Networks PAN-OS firewalls is currently being exploited by hackers. The high-severity flaw affects the management web interface, enabling unauthenticated attackers to bypass authentication and execute specific PHP scripts, potentially compromising system security.
Security Updates and Affected Versions
Palo Alto Networks has released patches for the following versions:
– 11.2.4-h4 or later
– 11.1.6-h1 or later
– 10.2.13-h3 or later
– 10.1.14-h9 or later
Note: PAN-OS 11.0, while affected, will not receive patches due to end-of-life status.
Vulnerability Details
Security researchers at Assetnote discovered the vulnerability, which exploits a path confusion between Nginx and Apache in PAN-OS. This allows attackers with network access to:
– Extract sensitive system data
– Retrieve firewall configurations
– Potentially modify system settings
Current Threat Landscape
GreyNoise monitoring platform has detected active exploitation attempts beginning February 13, 17:00 UTC, originating from multiple IP addresses. According to Macnica researcher Yutaka Sejiyama, over 4,400 PAN-OS devices currently expose their management interface online.
Recommended Actions
Organizations should:
1. Immediately upgrade to patched versions
2. Restrict access to firewall management interfaces
3. Monitor for suspicious activity
