{"cveID":"CVE-2025-0108","vendorProject":"Palo Alto Networks","product":"PAN-OS","vulnerabilityName":"Palo Alto Networks PAN-OS Authentication Bypass Vulnerability","dateAdded":"2025-02-18","shortDescription":"Palo Alto Networks PAN-OS contains an authentication bypass vulnerability in its management web interface. This vulnerability allows an unauthenticated attacker with network access to the management web interface to bypass the authentication normally required and invoke certain PHP scripts.","requiredAction":"Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.","dueDate":"2025-03-11","knownRansomwareCampaignUse":"Unknown","notes":"https://security.paloaltonetworks.com/CVE-2025-0108 ; https://nvd.nist.gov/vuln/detail/CVE-2025-0108","cwes":["CWE-306"],"year":2025,"state":"mapped","stale_reasons":[],"mappings":[{"domain":"enterprise","cve":"CVE-2025-0108","technique":"T1190","technique_name_at_mapping":"Exploit Public-Facing Application","mapping_type":"exploitation_technique","capability_group":"auth_bypass","comments":"This exploit is part of a chain of exploits (with CVE-2025-0108 and CVE-2024-9474) that can end with an attacker gaining root access to the system. This vulnerability allows the attacker to bypass authentication using the PAN-OS web management interface, as well as invoke PHP scripts. The attacker can also use their newfound privileged access to reconfigure the firewall, allowing for backdoors to be created.","references":["https://www.armis.com/threat-alert/breaking-down-palo-alto-networks-pan-os-vulnerability/"],"status":"complete","source_file":"kev-07.28.2025_attack-16.1-enterprise.json","attack_version":"16.1","kev_snapshot":"07/28/2025"},{"domain":"enterprise","cve":"CVE-2025-0108","technique":"T1055","technique_name_at_mapping":"Process Injection","mapping_type":"primary_impact","capability_group":"auth_bypass","comments":"This exploit is part of a chain of exploits (with CVE-2025-0108 and CVE-2024-9474) that can end with an attacker gaining root access to the system. This vulnerability allows the attacker to bypass authentication using the PAN-OS web management interface, as well as invoke PHP scripts. The attacker can also use their newfound privileged access to reconfigure the firewall, allowing for backdoors to be created.","references":["https://www.armis.com/threat-alert/breaking-down-palo-alto-networks-pan-os-vulnerability/"],"status":"complete","source_file":"kev-07.28.2025_attack-16.1-enterprise.json","attack_version":"16.1","kev_snapshot":"07/28/2025"},{"domain":"enterprise","cve":"CVE-2025-0108","technique":"T1565.001","technique_name_at_mapping":"Stored Data Manipulation","mapping_type":"primary_impact","capability_group":"auth_bypass","comments":"This exploit is part of a chain of exploits (with CVE-2025-0108 and CVE-2024-9474) that can end with an attacker gaining root access to the system. This vulnerability allows the attacker to bypass authentication using the PAN-OS web management interface, as well as invoke PHP scripts. The attacker can also use their newfound privileged access to reconfigure the firewall, allowing for backdoors to be created.","references":["https://www.armis.com/threat-alert/breaking-down-palo-alto-networks-pan-os-vulnerability/"],"status":"complete","source_file":"kev-07.28.2025_attack-16.1-enterprise.json","attack_version":"16.1","kev_snapshot":"07/28/2025"}],"techniques":[{"id":"T1055","domains":["enterprise"],"in_current_bundle":true,"live":true,"name_now":"Process Injection","name_at_mapping":"Process Injection","renamed":false,"revoked_by":null,"mapping_types":["primary_impact"],"sigma_rule_count":37,"has_detection_strategy":true},{"id":"T1190","domains":["enterprise"],"in_current_bundle":true,"live":true,"name_now":"Exploit Public-Facing Application","name_at_mapping":"Exploit Public-Facing Application","renamed":false,"revoked_by":null,"mapping_types":["exploitation_technique"],"sigma_rule_count":149,"has_detection_strategy":true},{"id":"T1565.001","domains":["enterprise"],"in_current_bundle":true,"live":true,"name_now":"Stored Data Manipulation","name_at_mapping":"Stored Data Manipulation","renamed":false,"revoked_by":null,"mapping_types":["primary_impact"],"sigma_rule_count":6,"has_detection_strategy":true}],"mapping_types":["exploitation_technique","primary_impact"],"has_exploitation_technique":true,"mapping_attack_versions":["16.1"],"mapping_domains":["enterprise"],"sigma_coverage":"full","sigma_rules_tagged_cve":[],"added_after_mapping_snapshot":false,"_source":"kevmap","_built":"2026-08-24 19:45 UTC","_attack_version":"19.2"}