CVE-2025-0130
Last modified
CVE-2025-0130 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. A missing exception check in Palo Alto Networks PAN-OS® software with the web proxy feature enabled allows an unauthenticated attacker to send a burst of maliciously crafted packets that causes the firewall to become unresponsive and eventually reboot. Repeated successful attempts to trigger this condition will cause the firewall to enter maintenance mode. This issue does not affect Cloud NGFW or Prisma Access.. EPSS estimates a 0.36% chance of exploitation in the next 30 days.
Description
A missing exception check in Palo Alto Networks PAN-OS® software with the web proxy feature enabled allows an unauthenticated attacker to send a burst of maliciously crafted packets that causes the firewall to become unresponsive and eventually reboot. Repeated successful attempts to trigger this condition will cause the firewall to enter maintenance mode. This issue does not affect Cloud NGFW or Prisma Access.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:U/V:C/RE:L/U:Amber
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Paloaltonetworks | Pan-Os | >= 11.1.0, < 11.1.6 | — |
| Paloaltonetworks | Pan-Os | >= 11.2.0, < 11.2.5 | H1 |
| Paloaltonetworks | Pan-Os | 11.1.7 | — |
References
- https://security.paloaltonetworks.com/CVE-2025-0130Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2025-0130?
How severe is CVE-2025-0130?
How do I fix CVE-2025-0130?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-0124An authenticated file deletion vulnerability in the Palo Alt…3.8
- CVE-2025-0125An improper input neutralization vulnerability in the manage…6.9
- CVE-2025-0126When configured using SAML, a session fixation vulnerability…8.3
- CVE-2025-0127A command injection vulnerability in Palo Alto Networks PAN-…7.1
- CVE-2025-0128A denial-of-service (DoS) vulnerability in the Simple Certif…8.7
- CVE-2025-0129An improper exception check in Palo Alto Networks Prisma Acc…9.3
- CVE-2025-0131An incorrect privilege management vulnerability in the OPSWA…7.1
- CVE-2025-0132A missing authentication vulnerability in Palo Alto Networks…6.9
- CVE-2025-0133A reflected cross-site scripting (XSS) vulnerability in the …2.7
- CVE-2025-0134A code injection vulnerability in the Palo Alto Networks Cor…6.5
- CVE-2025-0135An incorrect privilege assignment vulnerability in the Palo …3.3
- CVE-2025-0136Using the AES-128-CCM algorithm for IPSec on certain Palo Al…5.3
Are you affected by CVE-2025-0130?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
