PatchSiren

PatchSiren cyber security CVE debrief

CVE-2025-0123 Palo Alto Networks CVE debrief

A vulnerability in Palo Alto Networks PAN-OS software enables unlicensed administrators to view clear-text data captured using the packet capture feature in decrypted HTTP/2 data streams traversing network interfaces on the firewall. HTTP/1.1 data streams are not impacted. This vulnerability affects Siemens RUGGEDCOM APE1808 devices that incorporate Palo Alto Networks Virtual NGFW. The issue was disclosed in CISA advisory ICSA-24-338-02 on November 22, 2024, with the CVE added to the advisory on May 13, 2025. The vulnerability has a CVSS 3.1 score of 6.0 (MEDIUM severity). The attack vector is local, requiring high privileges, with a scope change that allows the vulnerable component to impact resources beyond its security scope. The confidentiality impact is rated HIGH, while integrity and availability impacts are NONE.

Vendor
Palo Alto Networks
Product
RUGGEDCOM APE1808
CVSS
MEDIUM 6
CISA KEV
Not listed in stored evidence
Original CVE published
2024-11-22
Original CVE updated
2025-06-10
Advisory published
2024-11-22
Advisory updated
2025-06-10

Who should care

Organizations operating Siemens RUGGEDCOM APE1808 devices with Palo Alto Networks Virtual NGFW, particularly in industrial control system (ICS) environments. Security teams responsible for firewall administration, network monitoring, and privileged access management should prioritize this vulnerability. Organizations subject to regulatory requirements for data confidentiality in industrial networks should also take note.

Technical summary

This vulnerability exists in the packet capture feature of Palo Alto Networks PAN-OS software when processing decrypted HTTP/2 data streams. Unlicensed administrators with local access and high privileges can exploit this flaw to view clear-text data from network traffic. The vulnerability does not affect HTTP/1.1 data streams. The scope change in the CVSS vector indicates that successful exploitation can affect resources beyond the vulnerable component's security scope. The affected product is Siemens RUGGEDCOM APE1808, an industrial networking device that incorporates Palo Alto Networks Virtual NGFW.

Defensive priority

MEDIUM

Recommended defensive actions

  • Upgrade Palo Alto Networks Virtual NGFW to version 11.1.8 per vendor guidance
  • Contact Palo Alto Networks customer support to receive patch and update information
  • Review administrator access controls to ensure least-privilege principles
  • Monitor for unauthorized packet capture activities on affected systems
  • Apply defense-in-depth strategies for industrial control systems per CISA guidance

Evidence notes

The source CISA CSAF advisory ICSA-24-338-02 documents this vulnerability as affecting Siemens RUGGEDCOM APE1808 with Palo Alto Networks Virtual NGFW. The advisory revision history confirms CVE-2025-0123 was added in version 1.4 on May 13, 2025. The CVSS vector indicates local attack vector, high privileges required, scope change, and high confidentiality impact.

Official resources

Disclosed via CISA ICS advisory ICSA-24-338-02 on November 22, 2024; CVE-2025-0123 added to advisory on May 13, 2025