CVE-2025-0108: PAN-OS Management Interface – Path Confusion to Authentication Bypass

CVE-2025-0108: PAN-OS Management Interface - Path Confusion to Authentication Bypass-渗透云记 - 专注于网络安全与技术分享
CVE-2025-0108: PAN-OS Management Interface – Path Confusion to Authentication Bypass
此内容为付费阅读,请付费后查看
100积分
付费阅读

漏洞标题

CVE-2025-0108: pan-os Management Interface – Path Confusion to Authentication Bypass

漏洞描述

A vulnerability in PAN-OS management interface allows authentication bypass through path confusion between Nginx and Apache handlers.The issue occurs due to differences in path processing between Nginx and Apache, where double URL encoding combined with directory traversal can bypass authentication checks enforced by X-pan-AuthCheck header.

PoC代码

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享