Home

Description

A missing exception check in Palo Alto Networks PAN-OS® software with the web proxy feature enabled allows an unauthenticated attacker to send a burst of maliciously crafted packets that causes the firewall to become unresponsive and eventually reboot. Repeated successful attempts to trigger this condition will cause the firewall to enter maintenance mode. This issue does not affect Cloud NGFW or Prisma Access.

PUBLISHED Reserved 2024-12-20 | Published 2025-05-14 | Updated 2025-05-15 | Assigner palo_alto




HIGH: 8.2CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/AU:Y/R:U/V:C/RE:L/U:Amber

Problem types

CWE-754 Improper Check for Unusual or Exceptional Conditions

Product status

Default status
unaffected

All (custom)
unaffected

Default status
unaffected

11.2.0 (custom) before 11.2.5
affected

11.1.0 (custom) before 11.1.6-h1
affected

10.2.0 (custom)
unaffected

10.1.0 (custom)
unaffected

Default status
unaffected

All (custom)
unaffected

Timeline

2025-05-14:Initial publication

Credits

Jari Pietila of Palo Alto Networks finder

References

security.paloaltonetworks.com/CVE-2025-0130 vendor-advisory

cve.org (CVE-2025-0130)

nvd.nist.gov (CVE-2025-0130)

Download JSON