PatchSiren cyber security CVE debrief
CVE-2025-0123 Palo Alto Networks CVE debrief
A vulnerability in Palo Alto Networks PAN-OS software enables unlicensed administrators to view clear-text data captured using the packet capture feature in decrypted HTTP/2 data streams traversing network interfaces on the firewall. HTTP/1.1 data streams are not impacted. This vulnerability affects Siemens RUGGEDCOM APE1808 devices that incorporate Palo Alto Networks Virtual NGFW. The issue was disclosed in CISA advisory ICSA-24-338-02 on November 22, 2024, with the CVE added to the advisory on May 13, 2025. The vulnerability has a CVSS 3.1 score of 6.0 (MEDIUM severity). The attack vector is local, requiring high privileges, with a scope change that allows the vulnerable component to impact resources beyond its security scope. The confidentiality impact is rated HIGH, while integrity and availability impacts are NONE.
- Vendor
- Palo Alto Networks
- Product
- RUGGEDCOM APE1808
- CVSS
- MEDIUM 6
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2024-11-22
- Original CVE updated
- 2025-06-10
- Advisory published
- 2024-11-22
- Advisory updated
- 2025-06-10
Who should care
Organizations operating Siemens RUGGEDCOM APE1808 devices with Palo Alto Networks Virtual NGFW, particularly in industrial control system (ICS) environments. Security teams responsible for firewall administration, network monitoring, and privileged access management should prioritize this vulnerability. Organizations subject to regulatory requirements for data confidentiality in industrial networks should also take note.
Technical summary
This vulnerability exists in the packet capture feature of Palo Alto Networks PAN-OS software when processing decrypted HTTP/2 data streams. Unlicensed administrators with local access and high privileges can exploit this flaw to view clear-text data from network traffic. The vulnerability does not affect HTTP/1.1 data streams. The scope change in the CVSS vector indicates that successful exploitation can affect resources beyond the vulnerable component's security scope. The affected product is Siemens RUGGEDCOM APE1808, an industrial networking device that incorporates Palo Alto Networks Virtual NGFW.
Defensive priority
MEDIUM
Recommended defensive actions
- Upgrade Palo Alto Networks Virtual NGFW to version 11.1.8 per vendor guidance
- Contact Palo Alto Networks customer support to receive patch and update information
- Review administrator access controls to ensure least-privilege principles
- Monitor for unauthorized packet capture activities on affected systems
- Apply defense-in-depth strategies for industrial control systems per CISA guidance
Evidence notes
The source CISA CSAF advisory ICSA-24-338-02 documents this vulnerability as affecting Siemens RUGGEDCOM APE1808 with Palo Alto Networks Virtual NGFW. The advisory revision history confirms CVE-2025-0123 was added in version 1.4 on May 13, 2025. The CVSS vector indicates local attack vector, high privileges required, scope change, and high confidentiality impact.
Sources and references
Verified primary and authoritative sources
-
CVE-2025-0123 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2025-0123
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2025-0123 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2025-0123
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2024/icsa-24-338-02.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/csaf/ssa-354569.json
Reference
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/html/ssa-354569.html
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-24-338-02
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://us-cert.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.