CVE-2025-0128
Published: Apr 11, 2025
Modified: Apr 11, 2025
Description
A denial-of-service (DoS) vulnerability in the Simple Certificate Enrollment Protocol (SCEP) authentication feature of Palo Alto Networks PAN-OS® software enables an unauthenticated attacker to initiate system reboots using a maliciously crafted packet. Repeated attempts to initiate a reboot causes the firewall to enter maintenance mode. Cloud NGFW is not affected by this vulnerability. Prisma® Access software is proactively patched and protected from this issue.
| Vendor | Product | Versions |
|---|---|---|
Palo Alto Networks | Cloud NGFW | unaffected All |
Palo Alto Networks | PAN-OS | affected 11.2.0 - < 11.2.3affected 11.1.0 - < 11.1.5affected 11.0.0 - < 11.0.6affected 10.2.0 - < 10.2.10-h17affected 10.1.0 - < 10.1.14-h11 |
Palo Alto Networks | Prisma Access | affected 10.2.0 - < 10.2.4-h36affected 11.2.0 - < 11.2.4-h5 |
Weaknesses (CWE)
References
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now