Evidence dossier

CVE-2025-0111

PAN-OS: Authenticated File Read Vulnerability in the Management Web Interface

Exploited in the wild (CISA KEV since Feb 20, 2025). palo_alto reports CVSS 4.0 7.1. Severity assessments differ within at least one CVSS version. EPSS estimates 2.0% exploit likelihood as of Aug 27, 2026.

60.266.7Priority evidence range
Evidence current through Aug 27, 2026, 6:09 PM UTC

As of Aug 27, 2026

Normalized restatement

An authenticated file read vulnerability in the Palo Alto Networks PAN-OS software enables an authenticated attacker with network access to the management web interface to read files on the PAN-OS filesystem that are readable by the “nobody” user. You can greatly reduce the risk of this issue by restricting access to the management web interface to only trusted internal IP addresses according to our recommended best practices deployment guidelines https://live.paloaltonetworks.com/t5/community-blogs/tips-amp-tricks-how-to-secure-the-management-access-of-your-palo/ba-p/464431 . This issue does not affect Cloud NGFW or Prisma Access software.

State
PUBLISHED
Published
Feb 12, 2025
Updated
Feb 26, 2026
Evidence coverage
86%

Evidence chronology

What was known when

Download this view's receipt →
  1. Source dateSource date omittedFirst observed by CASCA
    CISA-ADP

    Record text: CISA ADP Vulnrichment

    Inspect raw assertion
    Field
    container
    Value
    CISA ADP Vulnrichment
    Original evidence ↗
  2. Source dateSource date omittedFirst observed by CASCA
    palo_alto

    Record text: PAN-OS: Authenticated File Read Vulnerability in the Management Web Interface

    Inspect raw assertion
    Field
    container
    Value
    PAN-OS: Authenticated File Read Vulnerability in the Management Web Interface
    Original evidence ↗
  3. Source dateFirst observed by CASCA
    CISA KEV

    Exploitation cataloged: Palo Alto Networks PAN-OS File Read Vulnerability

    Inspect raw assertion
    Field
    observed_exploitation
    Value
    Palo Alto Networks PAN-OS File Read Vulnerability
    Original evidence ↗
  4. Source dateFirst observed by CASCA
    FIRST EPSS

    EPSS score: 1.96% probability · 78.85th percentile

    Inspect raw assertion
    Field
    model_probability
    Value
    Probability 0.019600000000; percentile 0.788490000000
    Original evidence ↗

Assessments differ

NVD6.5CVSS 3.1 · source date omitted
psirt@paloaltonetworks.com7.1CVSS 4.0 · source date omitted

Values are shown separately by source and CVSS version.

ExploitationCatalog member

CISA KEV · catalog date Feb 20, 2025 · first observed Jul 19, 2026

Exploit likelihood1.96%

FIRST EPSS · score date Aug 27, 2026 · 78.8th percentile · first observed Aug 27, 2026

SeverityAssessments differ

palo_alto · CVSS 4.0 · first observed Jul 19, 2026 · values shown separately below

Evidence detail

Source limits and decisions

Why each evidence state has this value

Outside this view’s verified evidence

Reason detail begins outside this selected snapshot; the state remains source-bound.

Source comparison

Who said what

CISA-ADPIndependent enrichment
Record text

CISA ADP Vulnrichment

Inspect raw assertion
Field
container
Value
CISA ADP Vulnrichment
Source dateSource date omittedFirst observed by CASCAOriginal evidence ↗
palo_altoOriginal assertion
Record text

PAN-OS: Authenticated File Read Vulnerability in the Management Web Interface

Inspect raw assertion
Field
container
Value
PAN-OS: Authenticated File Read Vulnerability in the Management Web Interface
Source dateSource date omittedFirst observed by CASCAOriginal evidence ↗
CISA KEVOriginal assertion
Exploitation cataloged

Palo Alto Networks PAN-OS File Read Vulnerability

Inspect raw assertion
Field
observed_exploitation
Value
Palo Alto Networks PAN-OS File Read Vulnerability
Source dateFirst observed by CASCAOriginal evidence ↗
FIRST EPSSOriginal assertion
EPSS score

1.96% probability · 78.85th percentile

Inspect raw assertion
Field
model_probability
Value
Probability 0.019600000000; percentile 0.788490000000
Source dateFirst observed by CASCAOriginal evidence ↗

Applicability

Cited product scope

Trace impact →
48Underlying assertions
1Canonical products
48Target assertions
0Constraint assertions

Grouped from 1 configuration nodes in this exact snapshot. Visual grouping is navigational; asset exposure and root cause require cited evidence.

Identity source boundaries
  • Cpe dictionary1,775,266 records · observed through 2026-07-21T06:45:29.809Z27d65b0f-b718-4b4f-bb79-c47c68d09dfa
  • Cpe match643,502 records · observed through 2026-07-21T08:13:17.697Z955dae73-7302-438b-aee1-058d7cc5d48e

4 scope groups

palo_alto · source assertedPalo Alto NetworksCloud NGFWDirect source scope
Unaffected: All (custom comparison)
Source-reported scope

Canonical linkage remains open; the cited source assertion is retained below.

Inspect raw assertion[{"status": "unaffected", "version": "All", "versionType": "custom"}]
palo_alto · source assertedPalo Alto NetworksPAN-OSDirect source scope
Affected: 10.1.0 to before 10.1.14-h9 (custom comparison)Affected: 10.2.0 to before 10.2.7-h24 (custom comparison)Affected: 11.1.0 to before 11.1.6-h1 (custom comparison)Affected: 11.2.0 to before 11.2.4-h4 (custom comparison)
Source-reported scope

Canonical linkage remains open; the cited source assertion is retained below.

Inspect raw assertion[{"status": "affected", "version": "10.1.0", "lessThan": "10.1.14-h9", "versionType": "custom"}, {"status": "affected", "version": "10.2.0", "lessThan": "10.2.7-h24", "versionType": "custom"}, {"status": "affected", "version": "11.1.0", "lessThan": "11.1.6-h1", "versionType": "custom"}, {"status": "affected", "version": "11.2.0", "lessThan": "11.2.4-h4", "versionType": "custom"}]
palo_alto · source assertedPalo Alto NetworksPrisma AccessDirect source scope
Unaffected: All (custom comparison)
Source-reported scope

Canonical linkage remains open; the cited source assertion is retained below.

Inspect raw assertion[{"status": "unaffected", "version": "All", "versionType": "custom"}]
NVD CPE · OPERATING SYSTEMpaloaltonetworkspan-osVulnerable target · 48 assertions
Any version (unconstrained) (>= 10.1.0, < 10.1.14); Any version (unconstrained) (>= 10.2.0, < 10.2.7); Any version (unconstrained) (>= 10.2.10, < 10.2.12); Any version (unconstrained) (>= 11.0.0, < 11.1.6); Any version (unconstrained) (>= 11.2.0, < 11.2.4); Version 10.1.14; Version 10.2.12; Version 10.2.13; Version 10.2.7; Version 10.2.8; Version 10.2.9; Version 11.1.6; Version 11.2.4Canonical identity product-612afb736440531327cd224402d663e14e2a3f421cc65267d8acade0f3b99df7Linked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:o:paloaltonetworks:pan-os:10.2.9:h18:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 33
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    ccc2a6da-eb48-42cd-9234-a80c3f6aefae
  2. cpe:2.3:o:paloaltonetworks:pan-os:10.2.8:h19:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 25
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    c889402f-138a-45b9-bbcf-91fd18a0b810
  3. cpe:2.3:o:paloaltonetworks:pan-os:10.1.14:h2:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 6
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    65949a49-03a7-491c-b327-127f050ac4f6
  4. cpe:2.3:o:paloaltonetworks:pan-os:10.2.9:h9:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 35
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    4e9eb9c6-78ba-4c66-a4bd-856bf27388ce
  5. cpe:2.3:o:paloaltonetworks:pan-os:10.2.13:h1:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 42
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    f1fc63b8-b8d9-4ec1-85ca-2e12b38acd3e
  6. cpe:2.3:o:paloaltonetworks:pan-os:10.2.9:h11:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 30
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    ceb258ee-2c6e-4a63-b04c-89c5f76b0878
  7. cpe:2.3:o:paloaltonetworks:pan-os:10.2.9:h19:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 34
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    046874f8-7da7-4e2a-99bf-509424e6ccbf
  8. cpe:2.3:o:paloaltonetworks:pan-os:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 1
    Logic
    OR
    Version bounds
    from including 10.2.0; through excluding 10.2.7
    Match ID
    243077cd-5021-4df3-8ac7-5b14f7fd9710
  9. cpe:2.3:o:paloaltonetworks:pan-os:10.2.7:h21:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 16
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    fa91a4e9-ce1e-4cb8-b717-4b0e314c0171
  10. cpe:2.3:o:paloaltonetworks:pan-os:10.1.14:-:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 5
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    b41a7115-a370-49e1-b162-24803e6dd2cb
  11. cpe:2.3:o:paloaltonetworks:pan-os:10.2.8:h3:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 26
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    cba2b4fa-16c2-41b9-856d-edc0caf7a164
  12. cpe:2.3:o:paloaltonetworks:pan-os:10.1.14:h6:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 8
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    6643574d-c024-440c-9392-004b7fa4498f
  13. cpe:2.3:o:paloaltonetworks:pan-os:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 4
    Logic
    OR
    Version bounds
    from including 11.2.0; through excluding 11.2.4
    Match ID
    7e4d3a51-0a40-4b19-aafc-a2484b1cf5d7
  14. cpe:2.3:o:paloaltonetworks:pan-os:10.2.8:h15:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 23
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    d1ecd1dc-5a05-4e4f-97f5-136ce777fab3
  15. cpe:2.3:o:paloaltonetworks:pan-os:10.2.8:h18:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 24
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    347e5938-24ff-4c2c-b823-988d34706e24
  16. cpe:2.3:o:paloaltonetworks:pan-os:10.2.7:h12:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 12
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    aa4994cb-6591-4b44-a5d7-3cdf540b97de
  17. cpe:2.3:o:paloaltonetworks:pan-os:10.2.8:h4:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 27
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    e5e6a893-2994-40a3-af35-8af068b0de42
  18. cpe:2.3:o:paloaltonetworks:pan-os:11.2.4:-:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 45
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    c01ad190-f3c2-4349-a063-8c5c78b725b9
  19. cpe:2.3:o:paloaltonetworks:pan-os:10.2.8:h10:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 21
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    f70fc9df-10c9-4ae5-b64b-3153e2e4e9e8
  20. cpe:2.3:o:paloaltonetworks:pan-os:10.2.12:-:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 36
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    3d33a0fb-7538-42bf-84e8-7ccd7eef9355
  21. cpe:2.3:o:paloaltonetworks:pan-os:10.2.12:h2:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 38
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    8ea4c2a7-18cd-4232-b08c-99befe497a57
  22. cpe:2.3:o:paloaltonetworks:pan-os:10.2.8:-:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 20
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    5d64390f-f870-4dbf-b0fe-bcdfe58c8685
  23. cpe:2.3:o:paloaltonetworks:pan-os:10.2.7:h18:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 14
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    34b083b9-cc1b-43cd-9a16-c018f7fa2ddb
  24. cpe:2.3:o:paloaltonetworks:pan-os:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 3
    Logic
    OR
    Version bounds
    from including 11.0.0; through excluding 11.1.6
    Match ID
    855047ca-abfa-4f3d-af98-245d14b75798
  25. cpe:2.3:o:paloaltonetworks:pan-os:10.2.13:-:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 41
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    c2b871a6-0636-42a0-9573-6f693d7753ad
  26. cpe:2.3:o:paloaltonetworks:pan-os:11.1.6:-:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 44
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    52c50a07-f4d8-4f1f-ba61-3429bb1721be
  27. cpe:2.3:o:paloaltonetworks:pan-os:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 0
    Logic
    OR
    Version bounds
    from including 10.1.0; through excluding 10.1.14
    Match ID
    19d52dc1-4441-4c88-b209-9b86fcc2162f
  28. cpe:2.3:o:paloaltonetworks:pan-os:10.2.12:h4:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 40
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    1fdb3d90-6656-49c5-9852-1f987baef0f9
  29. cpe:2.3:o:paloaltonetworks:pan-os:10.2.9:h14:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 31
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    0f481b0e-2353-4ab0-8a98-b0efbc409868
  30. cpe:2.3:o:paloaltonetworks:pan-os:10.2.9:h16:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 32
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    3f7fc771-527f-4619-b785-6ae1f4722074
  31. cpe:2.3:o:paloaltonetworks:pan-os:10.2.7:h8:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 19
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    1311961a-0ef6-488e-b0c2-edbd508587c9
  32. cpe:2.3:o:paloaltonetworks:pan-os:10.2.13:h2:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 43
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    60ce628f-c4cb-4342-8d71-de61a089b612
  33. cpe:2.3:o:paloaltonetworks:pan-os:10.2.7:h3:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 17
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    776e06ec-2fda-4664-ab43-9f6be9b897ca
  34. cpe:2.3:o:paloaltonetworks:pan-os:10.1.14:h8:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 9
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    7422f37d-7aba-4bec-8448-45a8f585d6f9
  35. cpe:2.3:o:paloaltonetworks:pan-os:10.2.8:h13:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 22
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    c3d6d552-6f33-496a-a505-5f59df3b487b
  36. cpe:2.3:o:paloaltonetworks:pan-os:10.2.7:h6:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 18
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    cbe09375-a863-42ff-813f-c20679d7c45c
  37. cpe:2.3:o:paloaltonetworks:pan-os:11.2.4:h1:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 46
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    30f4cd1c-6862-4279-8d2d-40b4d164222f
  38. cpe:2.3:o:paloaltonetworks:pan-os:10.2.7:-:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 10
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    a8c42d98-cf8f-456b-9d57-80bbdc2c8e74
  39. cpe:2.3:o:paloaltonetworks:pan-os:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 2
    Logic
    OR
    Version bounds
    from including 10.2.10; through excluding 10.2.12
    Match ID
    f9bd5e2d-61d2-4872-acd1-d5b442cc809d
  40. cpe:2.3:o:paloaltonetworks:pan-os:11.2.4:h2:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 47
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    a52b7a7a-483a-4075-b1e9-5c14b66f7fc3
  41. cpe:2.3:o:paloaltonetworks:pan-os:10.2.9:-:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 28
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    d814f3a3-5e9d-426d-a654-1346d9ece9b3
  42. cpe:2.3:o:paloaltonetworks:pan-os:10.2.12:h1:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 37
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    fb95d77f-1263-4d47-a0bb-94a6da937115
  43. cpe:2.3:o:paloaltonetworks:pan-os:10.2.12:h3:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 39
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    357b747e-f960-4aa9-8696-b3bd89933630
  44. cpe:2.3:o:paloaltonetworks:pan-os:10.2.7:h19:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 15
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    0d88cc33-7e32-4e82-8a94-70759e910510
  45. cpe:2.3:o:paloaltonetworks:pan-os:10.2.7:h16:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 13
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    a6ab7874-fe24-42ac-8e3a-822a70722126
  46. cpe:2.3:o:paloaltonetworks:pan-os:10.2.7:h1:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 11
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    b3aad4ba-22dd-43d3-91f1-8a6f5fbbf029
  47. cpe:2.3:o:paloaltonetworks:pan-os:10.1.14:h4:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 7
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    e8acb147-b4c1-4964-b538-eaa117cc6dc1
  48. cpe:2.3:o:paloaltonetworks:pan-os:10.2.9:h1:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 29
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    8c7e9211-7041-4720-b4b9-3ea95d425263

Affected-product evidence

Accepted scope and product mapping

0 canonical links · 0 source-reported links

Applicability remains source-scoped; safety and exposure remain unassessed.

Assessments

CVSS by origin

6.5
NVDCVSS 3.1 · role Primary · priority eligiblevalid_matchCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
7.1
psirt@paloaltonetworks.comCVSS 4.0 · role Secondary · priority eligiblevalid_matchCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:C/RE:M/U:Red
7.1
palo_altoCVSS 4.0 · role unknown · display onlyDirect record assessment retained outside normalized eligibilityCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/AU:N/R:U/V:C/RE:M/U:Red
5.9
palo_altoCVSS 4.0 · role unknown · display onlyDirect record assessment retained outside normalized eligibilityCVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/AU:N/R:U/V:C/RE:M/U:Amber

Evidence boundaries

  • KEV membership is authoritative for the catalog, not proof of exposure in any environment.
  • EPSS is a dated model probability and not an individual-environment prediction.
  • Affected or fixed status applies only to the exact cited product and version scope; remaining scope stays source-scoped.
  • NVD-carried upstream facts remain derivative; independent corroboration requires a separately authored source.
  • Only NVD metrics validated under the generation-bound calculator are Public Priority eligible; direct CVE record metrics remain display-only.
  • NVD CVSS source eligibility is closed: NVD-authored, exact record-source, or registered same-CVE container origin; unmapped sources remain display-only.
  • Affected-product evidence remains source-scoped; canonical linkage is required before applicability scoring.
  • Core replay supports the active and immediately prior generation; retrospective valid-at replay is deferred.
  • OSV aggregation and OSV-converted NVD material are not independent corroboration.
  • Red Hat facts are vendor assertions for the exact supplied products.
  • Nonmembership and not-yet-observed states are not proof of safety.