PAN-OS: Authenticated Admin Command Injection Vulnerability in PAN-OS VM-Series
Published Apr 11, 2025
7.1
HIGHCVSS 4.0
EPSS 0.57%
Description
A command injection vulnerability in Palo Alto Networks PAN-OS® software enables an authenticated administrator to bypass system restrictions and run arbitrary commands as a root user. This issue is only applicable to PAN-OS VM-Series. This issue does not affect firewalls that are already deployed.
Cloud NGFW and Prisma® Access are not affected by this vulnerability.
Affected products
-
Affected
- ≥ 10.1.0, < 10.1.14-h13
- ≥ 10.2.0, < 10.2.9
- ≥ 11.0.0, < 11.0.4
Unaffected
- 11.1.0
- 11.2.0
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Palo Alto Networks | Pan-OS | unaffected | Affected
Unaffected
|
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
VersionMinor VersionSuggested SolutionPAN-OS 11.2 on VM-Series
No action needed PAN-OS 11.1 on VM-Series
No action needed PAN-OS 11.0 on VM-Series 11.0.0 through 11.0.3 Upgrade to 11.0.4 or later PAN-OS 10.2 on VM-Series 10.2.0 through 10.2.8 Upgrade to 10.2.9 or later PAN-OS 10.1 on VM-Series 10.1.0 through 10.1.14 Upgrade to 10.1.14-h13 or later PAN-OS on non VM-Series platforms No action neededAll other older unsupported PAN-OS versions
Upgrade to a supported fixed version
PAN-OS 11.0 is EoL. We listed it in this section for completeness because we added a patch for PAN-OS 11.0 before it reached EoL. If you are running PAN-OS 11.0 in any of your firewalls, we strongly recommend that you upgrade from this EoL vulnerable version to a fixed version.
References (2)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-15134 Advisory
- https://security.paloaltonetworks.com/CVE-2025-0127 vendor-advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-15134 | Advisory | |
| https://security.paloaltonetworks.com/CVE-2025-0127 | vendor-advisory |
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
Red Hat
No data
GitHub
No data