6.9
CVE-2025-0109
- EPSS 0.73%
- Veröffentlicht 12.02.2025 21:15:16
- Zuletzt bearbeitet 12.02.2025 21:15:16
- Quelle psirt@paloaltonetworks.com
- CVE-Watchlists
- Unerledigt
An unauthenticated file deletion vulnerability in the Palo Alto Networks PAN-OS management web interface enables an unauthenticated attacker with network access to the management web interface to delete certain files as the “nobody” user; this includes limited logs and configuration files but does not include system files. You can greatly reduce the risk of this issue by restricting access to the management web interface to only trusted internal IP addresses according to our recommended best practices deployment guidelines https://live.paloaltonetworks.com/t5/community-blogs/tips-amp-tricks-how-to-secure-the-management-access-of-your-palo/ba-p/464431 . This issue does not affect Cloud NGFW or Prisma Access software.
Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerPalo Alto Networks
≫
Produkt
Cloud NGFW
Default Statusunaffected
Version
All
Status
unaffected
HerstellerPalo Alto Networks
≫
Produkt
PAN-OS
Default Statusunaffected
Version <
10.1.14-h9
Version
10.1.0
Status
affected
Version <
10.2.7-h24
Version
10.2.0
Status
affected
Version <
11.1.6-h1
Version
11.1.0
Status
affected
Version <
11.2.4-h4
Version
11.2.0
Status
affected
HerstellerPalo Alto Networks
≫
Produkt
Prisma Access
Default Statusunaffected
Version
All
Status
unaffected
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.73% | 0.72 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| psirt@paloaltonetworks.com | 6.9 | 0 | 0 |
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:C/RE:M/U:Amber
|
CWE-73 External Control of File Name or Path
The product allows user input to control or influence paths or file names that are used in filesystem operations.