NA
CVSSv3

CVE-2025-0109

CVSSv4: 6.9 | CVSSv3: NA | CVSSv2: NA | VMScore: 790 | EPSS: 0.00165 | KEV: Not Included
Published: 12/02/2025 Updated: 12/02/2025

Vulnerability Summary

Unauthenticated File Deletion Vulnerability in Palo Alto Networks PAN-OS Management Interface

Palo Alto Networks PAN-OS management web interface contains an unauthenticated file deletion vulnerability. An attacker with network access to the management web interface can delete certain files while operating as the "nobody" user. The impacted files include limited logs and configuration files, but system files remain protected. Palo Alto Networks recommends restricting management web interface access to trusted internal IP addresses to mitigate this risk. This vulnerability does not impact Cloud NGFW or Prisma Access software.

Solution

Version
Minor VersionSuggested Solution
PAN-OS 10.1
10.1.0 through 10.1.14
Upgrade to 10.1.14-h9 or later
PAN-OS 10.2
10.2.0 through 10.2.13
Upgrade to 10.2.13-h3 or later
PAN-OS 11.0 (EoL) Upgrade to a supported fixed versionPAN-OS 11.1
11.1.0 through 11.1.6
Upgrade to 11.1.6-h1 or later
PAN-OS 11.2
11.2.0 through 11.2.4
Upgrade to 11.2.4-h4 or laterNote: PAN-OS 11.0 reached end of life (EoL) on November 17, 2024. No additional fixes are planned for this release.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

paloaltonetworks pan-os 11.2.4

paloaltonetworks pan-os 11.2.3

paloaltonetworks pan-os 11.2.2

paloaltonetworks pan-os 11.2.1

paloaltonetworks pan-os 11.2.0

paloaltonetworks pan-os 11.1.6

paloaltonetworks pan-os 11.1.5

paloaltonetworks pan-os 11.1.4

paloaltonetworks pan-os 11.1.3

paloaltonetworks pan-os 11.1.2

paloaltonetworks pan-os 11.1.1

paloaltonetworks pan-os 11.1.0

paloaltonetworks pan-os 10.2.13

paloaltonetworks pan-os 10.2.12

paloaltonetworks pan-os 10.2.11

paloaltonetworks pan-os 10.2.10

paloaltonetworks pan-os 10.2.9

paloaltonetworks pan-os 10.2.8

paloaltonetworks pan-os 10.2.7

paloaltonetworks pan-os 10.2.6

paloaltonetworks pan-os 10.2.5

paloaltonetworks pan-os 10.2.4

paloaltonetworks pan-os 10.2.3

paloaltonetworks pan-os 10.2.2

paloaltonetworks pan-os 10.2.1

paloaltonetworks pan-os 10.2.0

paloaltonetworks pan-os 10.1.14

paloaltonetworks pan-os 10.1.13

paloaltonetworks pan-os 10.1.12

paloaltonetworks pan-os 10.1.11

paloaltonetworks pan-os 10.1.10

paloaltonetworks pan-os 10.1.9

paloaltonetworks pan-os 10.1.8

paloaltonetworks pan-os 10.1.7

paloaltonetworks pan-os 10.1.6

paloaltonetworks pan-os 10.1.5

paloaltonetworks pan-os 10.1.4

paloaltonetworks pan-os 10.1.3

paloaltonetworks pan-os 10.1.2

paloaltonetworks pan-os 10.1.1

paloaltonetworks pan-os 10.1.0

palo alto networks cloud ngfw

palo alto networks pan-os

palo alto networks prisma access