CVE Database
/

CVE-2025-0128

Back to search

CVE-2025-0128

Published: Apr 11, 2025

Modified: Apr 11, 2025

PUBLISHED

Description

A denial-of-service (DoS) vulnerability in the Simple Certificate Enrollment Protocol (SCEP) authentication feature of Palo Alto Networks PAN-OS® software enables an unauthenticated attacker to initiate system reboots using a maliciously crafted packet. Repeated attempts to initiate a reboot causes the firewall to enter maintenance mode. Cloud NGFW is not affected by this vulnerability. Prisma® Access software is proactively patched and protected from this issue.

VendorProductVersions

Palo Alto Networks

Cloud NGFW

unaffected
All

Palo Alto Networks

PAN-OS

affected
11.2.0 - < 11.2.3
affected
11.1.0 - < 11.1.5
affected
11.0.0 - < 11.0.6
affected
10.2.0 - < 10.2.10-h17
affected
10.1.0 - < 10.1.14-h11

Palo Alto Networks

Prisma Access

affected
10.2.0 - < 10.2.4-h36
affected
11.2.0 - < 11.2.4-h5

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now