PatchSiren cyber security CVE debrief
CVE-2025-0130 Palo Alto Networks CVE debrief
A missing exception check in Palo Alto Networks PAN-OS® software with the web proxy feature enabled allows an unauthenticated attacker to send a burst of maliciously crafted packets that causes the firewall to become unresponsive and eventually reboot. Repeated successful attempts to trigger this condition will cause the firewall to enter maintenance mode. This vulnerability affects Siemens RUGGEDCOM APE1808 devices that incorporate Palo Alto Networks Virtual NGFW. The issue was disclosed on November 22, 2024, with subsequent updates through June 10, 2025, when this CVE was added to the advisory. The vulnerability requires the web proxy feature to be enabled and is rated MEDIUM severity with a CVSS score of 5.9.
- Vendor
- Palo Alto Networks
- Product
- RUGGEDCOM APE1808
- CVSS
- MEDIUM 5.9
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2024-11-22
- Original CVE updated
- 2025-06-10
- Advisory published
- 2024-11-22
- Advisory updated
- 2025-06-10
Who should care
Organizations operating Siemens RUGGEDCOM APE1808 devices with Palo Alto Networks Virtual NGFW, particularly in industrial control system (ICS) and operational technology (OT) environments where firewall availability is critical for network segmentation and security. Security teams responsible for PAN-OS deployments with web proxy features enabled should prioritize assessment and remediation.
Technical summary
This vulnerability exists in Palo Alto Networks PAN-OS software when the web proxy feature is enabled. An unauthenticated attacker can exploit a missing exception check by sending a burst of maliciously crafted packets, causing the firewall to become unresponsive and eventually reboot. Repeated successful exploitation attempts can force the firewall into maintenance mode, resulting in extended service disruption. The attack vector is network-based with high attack complexity, requiring no privileges or user interaction. The vulnerability has no impact on confidentiality or integrity but results in high availability impact.
Defensive priority
medium
Recommended defensive actions
- Disable the web proxy feature if not necessary as an immediate mitigation
- Upgrade Palo Alto Networks Virtual NGFW to version 11.1.8 or later
- Contact Palo Alto Networks customer support to receive patch and update information
- Monitor firewall logs for unusual packet bursts or unexpected reboot events
- Review and apply CISA ICS recommended practices for defense-in-depth strategies
Evidence notes
Source: CISA CSAF advisory ICSA-24-338-02, with revision history confirming CVE-2025-0130 added in version 1.5 on 2025-06-10. The vulnerability description is drawn directly from the source item description field. Affected product confirmed as Siemens RUGGEDCOM APE1808 with Palo Alto Networks Virtual NGFW.
Sources and references
Verified primary and authoritative sources
-
CVE-2025-0130 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2025-0130
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2025-0130 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2025-0130
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2024/icsa-24-338-02.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/csaf/ssa-354569.json
Reference
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/html/ssa-354569.html
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-24-338-02
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://us-cert.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.