---
title: New Palo Alto vulnerability with active exploit attempts discovered
description: Palo Alto Networks (PAN) released updates for a vulnerability affecting its firewalls. Researchers published a PoC and current exploit attempts.
---

[Blog, News & Press Releases - Field Effect ](https://fieldeffect.com/blog)

# [New Palo Alto vulnerability with active exploit attempts discovered](https://fieldeffect.com/blog/palo-alto-firewall-vulnerability)

 Written by [Field Effect Security Intelligence Team](https://fieldeffect.com/blog/author/field-effect-security-intelligence-team) | Feb 14, 2025 6:50:34 PM

On February 12, 2025, Palo Alto Networks (PAN) released [security updates](https://security.paloaltonetworks.com/CVE-2025-0108) to address a high-severity vulnerability affecting its firewalls. Researchers have now published a [proof-of-concept (POC](https://github.com/iSee857/CVE-2025-0108-PoC)) and also [noted](https://www.securityweek.com/hackers-exploit-palo-alto-firewall-vulnerability-day-after-disclosure/) current attempts to exploit the vulnerability. 

This flaw is tracked as [CVE-2025-0108](https://nvd.nist.gov/vuln/detail/CVE-2025-0108) and could allow a bypass of authentication and access to the management web interface. It has been assigned a Common Vulnerability Scoring System (CVSS) base score of 7.8 out of 10. 

Palo Alto Networks reported that Prisma Access and Cloud NGFW deployments are not affected by the vulnerability. Note: CVE-2025-0108 affects PAN-OS v11.0 that reached end of life (EoL) on November 17, 2024. 

Source: [SecurityWeek](https://www.securityweek.com/hackers-exploit-palo-alto-firewall-vulnerability-day-after-disclosure)

## Analysis

The vulnerability can result in an authentication bypass issue in the PAN-OS management web interface. Someone with network access to the interface could exploit this flaw to invoke certain PHP scripts without proper authentication. This does not allow remote code execution but could compromise the integrity and confidentiality of the affected system. 

CVE-2025-0108 has a CVSS score of 7.8 when access is allowed to the management interface from external IP addresses on the Internet. Palo Alto Networks suggests that using a [jump box](https://en.wikipedia.org/wiki/Jump_serve) for accessing the management interface would reduce the CVSS score to 5.1. In that scenario, the attacks would require privileged access using only those IP addresses. 

According to researchers at [GreyNoise](https://www.greynoise.io/blog/greynoise-observes-active-exploitation-of-pan-os-authentication-bypass-vulnerability-cve-2025-0108), active scanning and attempts to compromise unpatched firewalls started shortly after the publication of technical details for this vulnerability. 

Mitigation

Field Effect’s Security Intelligence team constantly monitors the cyber threat landscape for vulnerabilities discovered in software, appliances, and operating systems. This research contributes to the timely deployment of signatures into Field Effect MDR to detect and mitigate the exploitation of these vulnerabilities. Field Effect MDR users are automatically notified when vulnerable software is detected in their environment and are encouraged to review these AROs (Actions-Recommendations-Observations) as quickly as possible via the Field Effect MDR portal. 

Field Effect strongly encourages users of potentially vulnerable Palo Alto firewalls to verify whether they have any firewall management interfaces exposed to the Internet by consulting the Palo Alto Customer Support Portal (Products > Assets > All Assets > Remediation Required). 

To reduce the threat posed by this vulnerability, users and network administrators should apply security patches for supported PAN-OS as soon as possible, and upgrade their EoL products to a supported version. We recommend configuring the devices and applications according to the vendor's recommended [best practices](https://www.cisa.gov/news-events/alerts/2024/11/13/palo-alto-networks-emphasizes-hardening-guidance).  

## Related Articles

- [Volt Typhoon’s KV-botnet dismantled by US authorities](https://fieldeffect.com/blog/volt-typhoon-kv-botnet-dismantled)
- [FBI derails Chinese ‘Raptor Train’](https://fieldeffect.com/blog/fbi-derails-chinese-raptor-train)
- [Juniper Networks enterprise routers targeted with magic backdoor](https://fieldeffect.com/blog/juniper-networks-enterprise-routers-targeted-magic-backdoor)

[View full post](https://fieldeffect.com/blog/palo-alto-firewall-vulnerability)

```json
{
  "@context" : "http://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "Field Effect Security Intelligence Team"
  },
  "dateModified" : "2025-02-14T18:59:51.415Z",
  "datePublished" : "2025-02-14T18:50:34Z",
  "headline" : "Active attempts to exploit Palo Alto vulnerability noted, exploit published",
  "image" : {
    "@type" : "ImageObject",
    "height" : 1353,
    "url" : "https://get.fieldeffect.com/hubfs/Blog-Thumb-Threat-Brief_04.jpg",
    "width" : 2400
  },
  "mainEntityOfPage" : "https://fieldeffect.com/blog/palo-alto-firewall-vulnerability",
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "height" : 60,
      "url" : "/hs/hsstatic/content_shared_assets/static-1.4092/img/default-amp-logo.png",
      "width" : 60
    },
    "name" : "Blog"
  }
}
```