CVE-2025-0137
CVE-2025-0137 is a medium-severity vulnerability with a CVSS 4.0 base score of 4.8. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-83.
Key facts
- Severity: Medium (CVSS 4.0 base score 4.8)
- EPSS exploit prediction: 0% (34th percentile)
- Actively exploited: Not listed in CISA KEV
- EU (EUVD) id: EUVD-2025-14905
- Weakness: CWE-83
- Published:
- Last modified:
Description
An improper input neutralization vulnerability in the management web interface of the Palo Alto Networks PAN-OS® software enables a malicious authenticated read-write administrator to impersonate another legitimate authenticated PAN-OS administrator. The attacker must have network access to the management web interface to exploit this issue. You greatly reduce the risk of this issue by restricting access to the management web interface to only trusted internal IP addresses according to our recommended critical deployment guidelines https://live.paloaltonetworks.com/t5/community-blogs/tips-amp-tricks-how-to-secure-the-management-access-of-your-palo/ba-p/464431 .
Frequently asked questions
- What is CVE-2025-0137?
- An improper input neutralization vulnerability in the management web interface of the Palo Alto Networks PAN-OS® software enables a malicious authenticated read-write administrator to impersonate another legitimate authenticated PAN-OS administrator. The attacker must have network access to the management web interface to exploit this issue. You greatly reduce the risk of this issue by restricting access to the management web interface to only trusted internal IP addresses according to our recommended critical deployment guidelines https://live.paloaltonetworks.com/t5/community-blogs/tips-amp-tricks-how-to-secure-the-management-access-of-your-palo/ba-p/464431 .
- How severe is CVE-2025-0137?
- CVE-2025-0137 has a CVSS 4.0 base score of 4.8, rated medium severity.
- Is CVE-2025-0137 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 0% (34th percentile), an estimate of the probability of exploitation in the next 30 days.
- How do I fix CVE-2025-0137?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround.
- Does CVE-2025-0137 have an EU (EUVD) identifier?
- Yes. CVE-2025-0137 is tracked in the ENISA EU Vulnerability Database (EUVD) as EUVD-2025-14905.
- When was CVE-2025-0137 published?
- CVE-2025-0137 was published on 2025-05-14 and last updated on 2026-06-17.
References
Other CWE-83 vulnerabilities
- CVE-2026-45118 — Critical (CVSS 9.3): MyBB is free and open source forum software. Prior to 1.8.40, the Contact module does not validate a redirect URL or…
- CVE-2023-32070 — Critical (CVSS 9.0): XWiki Platform is a generic wiki platform. Prior to version 14.6-rc-1, HTML rendering didn't check for dangerous…
- CVE-2024-26283 — High (CVSS 7.8): An attacker could have executed unauthorized scripts on top origin sites using a JavaScript URI when opening an…
- CVE-2026-49276 — High (CVSS 7.4): Kirby is an open-source content management system. Prior to 4.9.4 and 5.4.4, Kirby sites using the writer field in any…
- CVE-2025-4615 — High (CVSS 7.2): An improper input neutralization vulnerability in the management web interface of the Palo Alto Networks PAN-OS®…
- CVE-2025-0125 — Medium (CVSS 6.9): An improper input neutralization vulnerability in the management web interface of the Palo Alto Networks PAN-OS®…