PAN-OS management web interface

CVE-2025-0108: Management interface authentication bypass, chained for root access

A path confusion between Nginx and Apache lets anyone who can reach the PAN-OS management interface skip login. Exploited within a day of disclosure, and chained with CVE-2024-9474 to get root.

Published Updated

ExploitedYes, in CISA KEVAdded 18 Feb 2025
Ransomware useNot reportedPer CISA
SeverityHIGHCVSS 4.0 8.8
EPSS98%Chance of exploitation in 30 days
Public exploitYes
FixAvailable

Affected and fixed versions

Product / branchFixed in
PAN-OS 11.211.2.4-h4, 11.2.5 or later
PAN-OS 11.111.1.2-h18, 11.1.4-h13, 11.1.6-h1 or later
PAN-OS 10.210.2.7-h24, 10.2.8-h21, 10.2.9-h21, 10.2.10-h14, 10.2.11-h12, 10.2.12-h6, 10.2.13-h3 or later
PAN-OS 10.110.1.14-h9 or later
PAN-OS 11.0 and older (end of life)No fix. Upgrade to a supported fixed version
Cloud NGFW, Prisma AccessNot affected

Always confirm against the vendor advisory, which lists every fixed hotfix.

What it is

The PAN-OS management web interface sits behind two web servers. Nginx receives the request and decides whether login is required, passing its decision on in a header (X-pan-AuthCheck). Apache then processes the same request, decoding the URL a second time.

A double-encoded path like /unauth/%252e%252e/php/ztp_gate.php/... looks harmless to Nginx, which marks it as not needing authentication. Apache decodes it again, turns it into ../php/ztp_gate.php, and runs that PHP script with no login.

On its own, the bypass only lets an attacker run certain PHP scripts, not arbitrary code. The danger is the chain: attackers combined it with CVE-2024-9474 (privilege escalation to root) and CVE-2025-0111 (file read). Together they give full control of the firewall from the network.

Assetnote found the bug while studying Palo Alto’s fix for the November 2024 management interface chain, CVE-2024-0012 and CVE-2024-9474. The underlying design, where one server decides authentication and another interprets the path, was still exploitable.

Am I affected?

Only if someone untrusted can reach the management web interface of a firewall or Panorama running an affected version. That happens in two ways:

  1. The management port itself is reachable from the internet or an untrusted network.
  2. A management profile with HTTPS is attached to a dataplane interface in an untrusted zone. This is the one people miss. If you attach such a profile to the interface that hosts GlobalProtect, the management UI is usually reachable on port 4443 of your VPN address.

Palo Alto’s Customer Support Portal lists devices it has seen with internet-facing management: Products > Assets > All Assets > Remediation Required.

Cloud NGFW and Prisma Access are not affected. GlobalProtect portals and gateways themselves aren’t vulnerable unless a management profile is attached as described above.

What to do

1. Take the management interface off the internet. This is the real fix, and it protects you against the next management-plane bug too. Allow management access only from a dedicated management network or jump host, and remove management profiles (or at least HTTPS) from every interface in an untrusted zone.

2. Upgrade to a fixed hotfix on your branch. PAN-OS 11.0 and older branches are end of life and get no fix.

3. Block attempts in the meantime. With Threat Prevention, enable Threat IDs 510000 and 510001 (Applications and Threats content 8943 or later).

4. If the interface was exposed while unpatched, assume the chain may have been used. Check for compromise (below). If you find signs of it, follow the cleanup advice on the CVE-2024-9474 page: rebuild, then rotate credentials and keys stored on the device.

Detection

  • Web requests to the management interface containing /unauth/ followed by encoded traversal (%252e%252e, %2e%2e), especially toward /php/ztp_gate.php or with /PAN_help/ in the path.
  • Threat log hits for Threat IDs 510000 or 510001.
  • Unexpected configuration changes, new administrators or commits you don’t recognize in the configuration and system logs.
  • Signs of the full chain: the indicators listed on the CVE-2024-9474 page.

Sources

Page changelog

  • Full analysis published.

KEV status, EPSS score and vendor data refreshed automatically, last on 10 Oct 2026.

Get alerts

A notification when we publish a new analysis or a covered vendor gets a new actively exploited CVE. No account, no email.