CVE-2025-0130

PAN-OS: Firewall Denial-of-Service (DoS) in the Web-Proxy Feature via a Burst of Maliciously Crafted Packets

Severity
High 8.2
CVSS 4.0
Exploited
Not listed
EPSS
0.004
36.3th percentile
Discovered by
Vendor
Vendor-published field
Published
May 14, 2025
Assigned by palo_alto

Description

A missing exception check in Palo Alto Networks PAN-OS® software with the web proxy feature enabled allows an unauthenticated attacker to send a burst of maliciously crafted packets that causes the firewall to become unresponsive and eventually reboot. Repeated successful attempts to trigger this condition will cause the firewall to enter maintenance mode. This issue does not affect Cloud NGFW or Prisma Access.

Weakness: CWE-754

Affected products

Vendor Product Category Matched by
Palo Alto Networks PAN-OS Firewall / NGFW cna-assigner
Vendor-reported products (3)
  • Palo Alto Networks · Cloud NGFW — vendor states not affected
  • Palo Alto Networks · PAN-OS
  • Palo Alto Networks · Prisma Access — vendor states not affected

Credit

Jari Pietila of Palo Alto Networks

Vendor remediation

Version Minor Version Suggested Solution PAN-OS 11.2 11.2.0 through 11.2.4Upgrade to 11.2.5 or later. PAN-OS 11.111.1.0 through 11.1.7 Upgrade to 11.1.7-h2 or 11.1.8 or later. 11.1.0 through 11.1.6Upgrade to 11.1.6-h1 or 11.1.8 or later.PAN-OS 11.0 (EoL) Upgrade to a supported fixed version. PAN-OS 10.2 No action needed.PAN-OS 10.1 No action needed.All other unsupported PAN-OS versions Upgrade to a supported fixed version.

Something wrong here?