Security Advisory

CVE-2025-0128

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2025-04-11 02:03:22
Last updated 2025-04-11 16:01:46
Assigner palo_alto
State PUBLISHED

Description

A denial-of-service (DoS) vulnerability in the Simple Certificate Enrollment Protocol (SCEP) authentication feature of Palo Alto Networks PAN-OS® software enables an unauthenticated attacker to initiate system reboots using a maliciously crafted packet. Repeated attempts to initiate a reboot causes the firewall to enter maintenance mode. Cloud NGFW is not affected by this vulnerability. Prisma® Access software is proactively patched and protected from this issue.