Executive brief
An authenticated file read vulnerability in Palo Alto Networks PAN-OS allows an attacker with network access to the management web interface to read files on the filesystem. Exploitation is limited to files readable by the 'nobody' user.
Affected products
- Palo Alto Networks PAN-OS 10.1.x, 10.2.x
Timeline
- 2025-02-12: other: New CVE received from Palo Alto Networks
- 2025-02-20: disclosed: Vulnerability published
- 2025-02-20: kev added: Added to CISA Known Exploited Vulnerabilities catalog
- 2025-02-20: exploited: Reported as exploited in the wild