Home

Description

A denial-of-service (DoS) vulnerability in the Simple Certificate Enrollment Protocol (SCEP) authentication feature of Palo Alto Networks PAN-OS® software enables an unauthenticated attacker to initiate system reboots using a maliciously crafted packet. Repeated attempts to initiate a reboot causes the firewall to enter maintenance mode. Cloud NGFW is not affected by this vulnerability. Prisma® Access software is proactively patched and protected from this issue.

PUBLISHED Reserved 2024-12-20 | Published 2025-04-11 | Updated 2025-04-11 | Assigner palo_alto




HIGH: 8.7CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/AU:Y/R:U/V:C/RE:M/U:Amber

A user sends a malicious crafted packet through the firewall, which processes a malicious packet that causes this issue.

MEDIUM: 5.3CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:L/AU:Y/R:U/V:C/RE:M/U:Amber

For Prisma Access, this issue can only be initiated by authenticated end users that use a maliciously crafted packet.

Problem types

CWE-754 Improper Check for Unusual or Exceptional Conditions

Product status

Default status
unaffected

All (custom)
unaffected

Default status
unaffected

11.2.0 (custom) before 11.2.3
affected

11.1.0 (custom) before 11.1.5
affected

11.0.0 (custom) before 11.0.6
affected

10.2.0 (custom) before 10.2.10-h17
affected

10.1.0 (custom) before 10.1.14-h11
affected

Default status
unaffected

10.2.0 (custom) before 10.2.4-h36
affected

11.2.0 (custom) before 11.2.4-h5
affected

Timeline

2025-04-09:Initial Publication

Credits

Abyss Watcher finder

References

security.paloaltonetworks.com/CVE-2025-0128 vendor-advisory

cve.org (CVE-2025-0128)

nvd.nist.gov (CVE-2025-0128)

Download JSON