A denial-of-service (DoS) vulnerability in the Simple Certificate Enrollment Protocol (SCEP) authentication feature of Palo Alto Networks PAN-OS® software enables an unauthenticated attacker to initiate system reboots using a maliciously crafted packet. Repeated attempts to initiate a reboot causes the firewall to enter maintenance mode.
Cloud NGFW is not affected by this vulnerability. Prisma® Access software is proactively patched and protected from this issue.
CVSS
No CVSS.
References
Link | Resource |
---|---|
https://security.paloaltonetworks.com/CVE-2025-0128 |
Configurations
No configuration.
History
11 Apr 2025, 15:39
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
11 Apr 2025, 02:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-04-11 02:15
Updated : 2025-04-11 15:39
NVD link : CVE-2025-0128
Mitre link : CVE-2025-0128
CVE.ORG link : CVE-2025-0128
JSON object : View
Products Affected
No product.
CWE
CWE-754
Improper Check for Unusual or Exceptional Conditions