CVE-2025-0111MEDIUM 6.5CISA KEVEPSS p76.5%
CVE-2025-0111Palo Alto Networks PAN-OS File Read Vulnerability
Palo Alto Networks / PAN-OS
Description
Palo Alto Networks PAN-OS contains an external control of file name or path vulnerability. Successful exploitation enables an authenticated attacker with network access to the management web interface to read files on the PAN-OS filesystem that are readable by the “nobody” user.
Scoring
| CVSS 3.1 | 6.5 (MEDIUM) |
| Vector | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
| EPSS | 1.86% probability of exploitation · percentile 76.5% · 2026-06-19T12:03:05Z |
| Published | 2025-02-12 |
| Last modified | 2025-11-04 |
CISA KEV entry
Added to KEV: 2025-02-20
Underlying weaknesses· 2
References
2
| Type | Target | Confidence | Tier |
|---|---|---|---|
| Weakness | Externally Controlled Reference to a Resource in Another Spherecwe-610 | 0% | live |
| Weakness | External Control of File Name or Pathcwe-73 | 0% | live |
(incoming)1
| Type | Target | Confidence | Tier |
|---|---|---|---|
| KEVEntry | Palo Alto Networks PAN-OS File Read Vulnerabilitykev-cve-2025-0111 | 0% | live |
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.