PAN-OS Management Interface - Path Confusion to Authentication Bypass
CVE-2025-0108
Verified
Description
A vulnerability in PAN-OS management interface allows authentication bypass through path confusion between Nginx and Apache handlers.The issue occurs due to differences in path processing between Nginx and Apache, where double URL encoding combined with directory traversal can bypass authentication checks enforced by X-pan-AuthCheck header.
Severity
Critical
CVSS Score
10
Exploit Probability
98%
Affected Product
pan-os
Published Date
February 13, 2025
Template Author
halencarjunior, ritikchaddha
CVE-2025-0108.yaml
10.0Score
CVSS Metrics
CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
CVE ID:
cve-2025-0108
CWE ID:
cwe-287
Remediation Steps
Upgrade to the patched version of PAN-OS as specified in the vendor security advisory.