Are Your Networks Protected Against PAN-OS and SonicOS Vulnerabilities?

Article Highlights
Off On

In an era where cyber threats are increasingly sophisticated and relentless, cybersecurity vigilance is of utmost importance. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has recently added two crucial security vulnerabilities affecting Palo Alto Networks PAN-OS and SonicWall SonicOS SSLVPN to its Known Exploited Vulnerabilities (KEV) catalog, highlighting the serious and urgent nature of these issues. These vulnerabilities, due to evidence of active exploitation, stress the necessity for organizations to be proactive in their defense strategies. Specifically, the vulnerabilities identified are CVE-2025-0108, which involves an authentication bypass in the PAN-OS management web interface, and CVE-2024-53704, an improper authentication vulnerability in the SonicWall SSLVPN.

The Scope of the Vulnerabilities

The first vulnerability, CVE-2025-0108, has a CVSS score of 7.8 and poses a significant risk as it allows attackers to bypass authentication mechanisms in the PAN-OS management web interface. This vulnerability has already been confirmed by Palo Alto Networks as actively exploited, with potential chaining with other vulnerabilities such as CVE-2024-9474 to gain further unauthorized access. This chaining capability amplifies the danger as it provides a pathway for multiple attack vectors to be executed simultaneously. GreyNoise, a threat intelligence firm, reported an alarming increase in attack activities, identifying 25 malicious IP addresses exploiting CVE-2025-0108. Noteworthy is the geographical spread of these attacks, prominently from the U.S., Germany, and the Netherlands, indicating the widespread and international scope of this particular threat.

Addressing the SonicOS SSLVPN Threat

The second highlighted vulnerability, CVE-2024-53704, has a CVSS score of 8.2 and pertains to SonicWall’s SonicOS SSLVPN. This vulnerability allows improper authentication, posing a severe risk for network security. The exploitation of this vulnerability was significantly magnified after the release of a proof-of-concept by Bishop Fox, leading to its weaponization as reported by the cybersecurity company Arctic Wolf. The active exploitation of this vulnerability shows the rapid pace at which cyber adversaries can adapt and deploy new techniques after discovering proof of concept. SonicWall users need to understand the ramifications of this exploit, as it can lead to unauthorized access and potential data breaches.

Recognizing these threats is paramount for all users, emphasizing the urgent need for robust security measures and protective actions to mitigate risks effectively. Rapid response and updated defenses are essential in countering the threat posed by this critical security flaw.

Explore more

How Firm Size Shapes Embedded Finance Strategy

The rapid transformation of mundane business platforms into sophisticated financial ecosystems has effectively redrawn the competitive boundaries for companies operating in the modern economy. In this environment, the integration of banking, payments, and lending services directly into a non-financial company’s digital interface is no longer a luxury for the avant-garde but a baseline requirement for economic viability. Whether a company

What Is Embedded Finance vs. BaaS in the 2026 Landscape?

The modern consumer no longer wakes up with the intention of visiting a bank, because the very concept of a financial institution has migrated from a physical storefront into the digital oxygen of everyday life. This transformation marks the definitive end of banking as a standalone chore, replacing it with a fluid experience where capital management is an invisible byproduct

How Can Payroll Analytics Improve Government Efficiency?

While the hum of a government office often suggests a routine of paperwork and protocol, the digital pulses within its payroll systems represent the heartbeat of a nation’s economic stability. In many public administrations, payroll data is viewed as little more than a digital receipt—a record of transactions that concludes once a salary reaches a bank account. Yet, this information

Global RPA Market to Hit $50 Billion by 2033 as AI Adoption Surges

The quiet hum of high-speed data processing has replaced the frantic clicking of keyboards in modern back offices, marking a permanent shift in how global businesses manage their most critical internal operations. This transition is not merely about speed; it is about the fundamental transformation of human-led workflows into self-sustaining digital systems. As organizations move deeper into the current decade,

New AGILE Framework to Guide AI in Canada’s Financial Sector

The quiet hum of servers across Canada’s financial heartland now dictates more than just basic transactions; it increasingly determines who qualifies for a mortgage or how a retirement fund reacts to global volatility. As algorithms transition from the shadows of back-office automation to the forefront of consumer-facing decisions, the stakes for oversight have never been higher. The findings from the