CVE-2025-0130: Palo Alto Networks PAN-OS
High severity, CVSS 7.5. EPSS: 0.4% chance of exploitation in the next 30 days.
A missing exception check in Palo Alto Networks PAN-OS® software with the web proxy feature enabled allows an unauthenticated attacker to send a burst of maliciously crafted packets that causes the firewall to become unresponsive and eventually reboot. Repeated successful attempts to trigger this condition will cause the firewall to enter maintenance mode. This issue does not affect Cloud NGFW or Prisma Access.
Affected products
- Palo Alto Networks PAN-OS: from 11.1.0, before 11.1.6 (fixed in 11.1.6); from 11.2.0, before 11.2.5 (fixed in 11.2.5); version 11.1.7 only
Published 2025-05-14. Last modified 2026-06-17.