CVE-2025-0128: Palo Alto Networks Cloud Ngfw

High severity, CVSS 8.7. EPSS: 0.3% chance of exploitation in the next 30 days.

A denial-of-service (DoS) vulnerability in the Simple Certificate Enrollment Protocol (SCEP) authentication feature of Palo Alto Networks PAN-OS® software enables an unauthenticated attacker to initiate system reboots using a maliciously crafted packet. Repeated attempts to initiate a reboot causes the firewall to enter maintenance mode. Cloud NGFW is not affected by this vulnerability. Prisma® Access software is proactively patched and protected from this issue.

Affected products

  • Palo Alto Networks Cloud Ngfw
  • Palo Alto Networks PAN-OS: from 11.2.0, before 11.2.3 (fixed in 11.2.3); from 11.1.0, before 11.1.5 (fixed in 11.1.5); from 11.0.0, before 11.0.6 (fixed in 11.0.6); from 10.2.0, before 10.2.10-h17 (fixed in 10.2.10-h17); from 10.1.0, before 10.1.14-h11 (fixed in 10.1.14-h11)
  • Palo Alto Networks Prisma Access: from 10.2.0, before 10.2.4-h36 (fixed in 10.2.4-h36); from 11.2.0, before 11.2.4-h5 (fixed in 11.2.4-h5)

Published 2025-04-11. Last modified 2026-06-17.