Palo Alto Networks has recently disclosed a critical vulnerability in its PAN-OS network security operating system, tracked as CVE-2025-0108, which allows attackers to bypass authentication on the management web interface. Additionally, Palo Alto Networks recommends restricting access to the management web interface by whitelisting trusted internal IP addresses as a best practice. Organizations using PAN-OS should act swiftly to patch affected systems and implement robust access controls for their management interfaces to mitigate potential exploitation risks. Cyber Security News is a Dedicated News Platform For Cyber News, Cyber Attack News, Hacking News & Vulnerability Analysis. Kaaviya is a Security Editor and fellow reporter with Cyber Security News. While this does not allow remote code execution directly, it poses severe risks to the confidentiality and integrity of PAN-OS systems by exposing sensitive administrative functionalities. The flaw highlights architectural weaknesses in the interaction between Nginx and Apache, two key components of the management interface.
This Cyber News was published on cybersecuritynews.com. Publication date: Thu, 13 Feb 2025 09:15:22 +0000