LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2025-0111: Palo Alto Networks PAN-OS File Read Vulnerability

RBRecent Breaches Vulnerability Intelligence·Feb 20, 2025
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Mar 13, 2025
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2025-0111 to its Known Exploited Vulnerabilities catalog on Feb 20, 2025, with a federal patch deadline of Mar 13, 2025 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Palo Alto Networks PAN-OS contains an external control of file name or path vulnerability. Successful exploitation enables an authenticated attacker with network access to the management web interface…

CVE-2025-0111 is a file-read vulnerability in Palo Alto Networks PAN-OS. An authenticated attacker who can reach the management web interface can read certain files on the PAN-OS filesystem that are accessible to the “nobody” user. Because the management plane often holds configuration, credentials, and operational data, successful abuse can give an attacker sensitive information that supports further compromise of the firewall or the networks it protects. Teams should treat exposure of the management interface as high priority and confirm exact impact and fixed releases against the vendor advisory.

How it works

The weakness is classified as CWE-73, external control of file name or path. In this class of flaw, user-supplied input influences which file the application opens or reads without sufficient validation or restriction. According to the CISA summary, an attacker who is already authenticated and has network access to the PAN-OS management web interface can cause the system to read files that the “nobody” user is permitted to access. The result is unauthorized disclosure of filesystem contents rather than remote code execution by itself. Exact request parameters, path constraints, and any required privileges beyond authentication are not detailed in the public summary; defenders must consult the Palo Alto Networks advisory for precise mechanics and any prerequisites.

Am I affected? How to find it in your systems

PAN-OS runs on Palo Alto Networks next-generation firewalls and related appliances that provide network security services. The vulnerability is reachable through the management web interface, so any device whose management plane is network-accessible is in scope until proven otherwise.

If you cannot determine version or exposure status quickly, assume the device is potentially affected until the advisory confirms otherwise.

How to remediate

The primary remediation is to apply the vendor-supplied update that addresses CVE-2025-0111. Follow Palo Alto Networks’ published instructions for the specific PAN-OS release stream running on each device; test the update in a non-production environment when operational constraints allow, then deploy according to your change process. After patching, verify the new version is active and re-check that the management interface is still properly restricted.

Beyond the patch, harden the management plane for this class of issue:

Confirm all version-specific steps and any additional vendor mitigations against the official advisory.

If you can't patch immediately

Until the update can be applied, reduce exposure with compensating controls:

These measures lower risk but do not eliminate the vulnerability; schedule the official patch as soon as operationally feasible. CISA’s required action is to apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

If your data may have been exposed

Actively exploited vulnerabilities of this type can lead to data exposure or broader breaches once an attacker obtains readable files containing credentials, keys, or configuration. Known ransomware use of CVE-2025-0111 is not documented in the provided information. If you suspect the management interface was reachable by unauthorized parties, treat any sensitive material that the “nobody” user could read as potentially compromised, rotate affected credentials, and review firewall and downstream system logs for follow-on activity. You can also run a free exposure scan of your email addresses against known breach data sets to check whether related accounts appear in prior incidents.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedPalo Alto Networks · PAN-OS
WeaknessCWE-73
Added to CISA KEVFeb 20, 2025
Federal patch deadlineMar 13, 2025
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities