Full Report
Palo Alto Networks warns that hackers are actively exploiting a critical authentication bypass flaw (CVE-2025-0108) in PAN-OS firewalls, chaining it with two other vulnerabilities to breach devices in active attacks. [...]
Analysis Summary
# Vulnerability: Exploited Chain Vulnerability in PAN-OS Web Management Interface
## CVE Details
- CVE ID: CVE-2025-0108, CVE-2024-9474, CVE-2025-0111
- CVSS Score: Not explicitly stated, but **CVE-2025-0108** is added to CISA KEV, indicating high severity/active exploitation.
- CWE: Not explicitly stated (likely related to Authentication Bypass/Improper Access Control given context).
## Affected Systems
- Products: Palo Alto Networks PAN-OS
- Versions: Unpatched and unsecured devices with the web management interface exposed to the internet.
- Configurations: Devices whose web management interface is exposed externally.
## Vulnerability Description
Palo Alto Networks observed exploit attempts chaining three vulnerabilities: **CVE-2025-0108**, **CVE-2024-9474**, and **CVE-2025-0111**. These flaws are leveraged against unpatched PAN-OS web management interfaces. The chaining of these vulnerabilities can reportedly be abused to download configuration files and other sensitive system information.
## Exploitation
- Status: **Exploited in the wild** (Palo Alto Networks confirmed exploitation attempts). Exploitation activity has increased significantly, with GreyNoise observing 25 distinct attacking IP addresses, up from 2 initially.
- Complexity: Implied **Low to Medium**, as publicly exposed devices are being widely targeted. Exploitation requires chaining the three flaws.
- Attack Vector: **Network** (Specifically via the web management interface).
## Impact
- Confidentiality: **High** (Ability to download configuration files and sensitive information).
- Integrity: Not explicitly detailed, but configuration manipulation/access implies risk.
- Availability: Not explicitly detailed, but device compromise could lead to availability impact.
## Remediation
### Patches
The article confirms that patches for **CVE-2025-0108** and **CVE-2025-0111** are available, but monitoring shows many devices remain unpatched. **CVE-2024-9474** was patched previously. Administrators should apply all relevant security updates for PAN-OS immediately.
### Workarounds
The CISA advisory provided a deadline, suggesting available updates/mitigations should be applied, or the product should be taken out of service. The primary workaround is updating/patching. **Crucially, administrators are advised to secure the web management interface away from direct internet exposure.**
## Detection
- Indicators of Compromise (IoCs): Active scanning and exploitation attempts originating from multiple geographic locations (US, Germany, Netherlands mentioned).
- Detection methods and tools: Network monitoring tools tracking unusual access patterns or configuration file retrieval attempts targeting the PAN-OS management interface. GreyNoise has been tracking malicious IP addresses associated with CVE-2025-0108.
## References
- Vendor Advisory: securityadvisories.paloaltonetworks.com/CVE-2025-0108 (Defanged)
- CISA KEV: cisa.gov/known-exploited-vulnerabilities-catalog?search_api_fulltext=CVE-2025-0108 (Defanged)
- GreyNoise Report: greynoise.io/blog/greynoise-observes-active-exploitation-of-pan-os-authentication-bypass-vulnerability-cve-2025-0108#GreyNoise (Defanged)