6.9
CVE-2025-0109
- EPSS 0.14%
- Veröffentlicht 12.02.2025 21:15:16
- Zuletzt bearbeitet 15.04.2026 00:35:42
- Quelle psirt@paloaltonetworks.com
- CVE-Watchlists
- Unerledigt
PAN-OS: Unauthenticated File Deletion Vulnerability on the Management Web Interface
An unauthenticated file deletion vulnerability in the Palo Alto Networks PAN-OS management web interface enables an unauthenticated attacker with network access to the management web interface to delete certain files as the “nobody” user; this includes limited logs and configuration files but does not include system files. You can greatly reduce the risk of this issue by restricting access to the management web interface to only trusted internal IP addresses according to our recommended best practices deployment guidelines https://live.paloaltonetworks.com/t5/community-blogs/tips-amp-tricks-how-to-secure-the-management-access-of-your-palo/ba-p/464431 . This issue does not affect Cloud NGFW or Prisma Access software.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerPalo Alto Networks
≫
Produkt
Cloud NGFW
Default Statusunaffected
Version
All
Status
unaffected
HerstellerPalo Alto Networks
≫
Produkt
PAN-OS
Default Statusunaffected
Version
10.1.0
Version <
10.1.14-h9
Status
affected
Version
10.2.0
Version <
10.2.7-h24
Status
affected
Version
11.1.0
Version <
11.1.6-h1
Status
affected
Version
11.2.0
Version <
11.2.4-h4
Status
affected
HerstellerPalo Alto Networks
≫
Produkt
Prisma Access
Default Statusunaffected
Version
All
Status
unaffected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.14% | 0.333 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| psirt@paloaltonetworks.com | 6.9 | 0 | 0 |
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:C/RE:M/U:Amber
|
CWE-73 External Control of File Name or Path
The product allows user input to control or influence paths or file names that are used in filesystem operations.