PatchSiren

PatchSiren cyber security CVE debrief

CVE-2025-0130 Palo Alto Networks CVE debrief

A missing exception check in Palo Alto Networks PAN-OS® software with the web proxy feature enabled allows an unauthenticated attacker to send a burst of maliciously crafted packets that causes the firewall to become unresponsive and eventually reboot. Repeated successful attempts to trigger this condition will cause the firewall to enter maintenance mode. This vulnerability affects Siemens RUGGEDCOM APE1808 devices that incorporate Palo Alto Networks Virtual NGFW. The issue was disclosed on November 22, 2024, with subsequent updates through June 10, 2025, when this CVE was added to the advisory. The vulnerability requires the web proxy feature to be enabled and is rated MEDIUM severity with a CVSS score of 5.9.

Vendor
Palo Alto Networks
Product
RUGGEDCOM APE1808
CVSS
MEDIUM 5.9
CISA KEV
Not listed in stored evidence
Original CVE published
2024-11-22
Original CVE updated
2025-06-10
Advisory published
2024-11-22
Advisory updated
2025-06-10

Who should care

Organizations operating Siemens RUGGEDCOM APE1808 devices with Palo Alto Networks Virtual NGFW, particularly in industrial control system (ICS) and operational technology (OT) environments where firewall availability is critical for network segmentation and security. Security teams responsible for PAN-OS deployments with web proxy features enabled should prioritize assessment and remediation.

Technical summary

This vulnerability exists in Palo Alto Networks PAN-OS software when the web proxy feature is enabled. An unauthenticated attacker can exploit a missing exception check by sending a burst of maliciously crafted packets, causing the firewall to become unresponsive and eventually reboot. Repeated successful exploitation attempts can force the firewall into maintenance mode, resulting in extended service disruption. The attack vector is network-based with high attack complexity, requiring no privileges or user interaction. The vulnerability has no impact on confidentiality or integrity but results in high availability impact.

Defensive priority

medium

Recommended defensive actions

  • Disable the web proxy feature if not necessary as an immediate mitigation
  • Upgrade Palo Alto Networks Virtual NGFW to version 11.1.8 or later
  • Contact Palo Alto Networks customer support to receive patch and update information
  • Monitor firewall logs for unusual packet bursts or unexpected reboot events
  • Review and apply CISA ICS recommended practices for defense-in-depth strategies

Evidence notes

Source: CISA CSAF advisory ICSA-24-338-02, with revision history confirming CVE-2025-0130 added in version 1.5 on 2025-06-10. The vulnerability description is drawn directly from the source item description field. Affected product confirmed as Siemens RUGGEDCOM APE1808 with Palo Alto Networks Virtual NGFW.

Sources and references

Verified primary and authoritative sources

  • CVE-2025-0130 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2025-0130

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2025-0130 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2025-0130

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2024/icsa-24-338-02.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/csaf/ssa-354569.json

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/html/ssa-354569.html

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-24-338-02

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://us-cert.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.