Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Yes, some PA-Series hardware firewalls are in scope, but Palo Alto Networks says the listed exploitable firmware issues require an attacker to have already compromised PAN-OS and gained root privileges, or to have physical access to open the appliance. The vendor bulletin identifies the PA-3200, PA-5200, and PA-7000 families for its listed concerns; it excludes other firewall platforms, including CN-Series and VM-Series. The advisory’s latest listed update is June 24, 2025, so check Palo Alto Networks’ bulletin for any changes after that date.

What Palo Alto Networks says about the vulnerabilities

Palo Alto Networks published security bulletin PAN-SA-2025-0003 on January 23, 2025, and updated it on June 24, 2025. It addresses reported vulnerabilities in firmware and bootloaders included with certain PA-Series hardware firewalls.

The vendor says the listed exploitable issues do not, by themselves, compromise PAN-OS. Exploitation requires either an attacker who has already compromised PAN-OS and obtained root Linux privileges, or physical access to open the appliance. Palo Alto Networks also says that, on up-to-date systems with secured management interfaces configured according to its best practices, users and PAN-OS administrators do not have BIOS firmware access or permission to modify it under normal conditions.

Which Palo Alto firewall models are affected?

The bulletin names the PA-3200, PA-5200, and PA-7000 families for the listed concerns. For the six InsydeH2O vulnerabilities, the specified systems are those families with an SMC-B installed. Palo Alto Networks says other hardware firewalls are not affected.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Product or family Vendor bulletin status
PA-3200, PA-5200, PA-7000 Identified as affected families for listed concerns; the InsydeH2O items specify systems with an SMC-B installed.
Other hardware firewalls Palo Alto Networks says they are not affected.
Cloud NGFW and Prisma Access Listed as unaffected.
CN-Series and VM-Series Explicitly excluded from the bulletin’s concerns.

Separately, SecurityWeek reported on January 24, 2025, that Eclypsium acquired and examined PA-3260, PA-1410, and PA-415 appliances. Those are the devices examined by Eclypsium as reported by the outlet; that report should not be read as changing the vendor’s affected-family scope.

Does BootHole affect PAN-OS firewalls?

The bulletin includes CVE-2020-10713, known as BootHole, and lists PAN-OS 10.2.14 and PAN-OS 11.1.8 as fixed versions. Palo Alto Networks’ stated prerequisite remains important: BootHole is not described as a standalone remote route into the firewall; an attacker would first need the specified PAN-OS compromise and root privileges, or physical access to open the device.

SecurityWeek reported Eclypsium’s concern that an attacker might obtain the necessary privileges by chaining PAN-OS vulnerabilities CVE-2024-0012 and CVE-2024-9474. That is researcher context relayed by the outlet, not independent confirmation here that such a chain works in a given deployment.

How the listed vulnerability classes differ

The bulletin distinguishes between issues for which it lists fixes or possible firmware work and issues Palo Alto Networks says do not apply under PAN-OS conditions.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Issue Palo Alto Networks’ assessment and status in the bulletin
BootHole, CVE-2020-10713 Fixed versions listed: PAN-OS 10.2.14 and 11.1.8.
Six InsydeH2O issues: CVE-2021-33627, CVE-2021-42060, CVE-2021-42554, CVE-2021-43323, CVE-2021-45970, CVE-2022-24030 The vendor said it was working with third-party vendors to develop any firmware updates that might be needed for the specified hardware. The bulletin’s last listed update is June 24, 2025; this statement does not establish later firmware status.
LogoFAIL, CVE-2023-40238 Palo Alto Networks says it is not exploitable under PAN-OS conditions.
PixieFAIL, CVE-2023-45229 through CVE-2023-45237 Palo Alto Networks says these do not affect PAN-OS because the BIOS network stack is disabled.
CVE-2023-1017 Palo Alto Networks says it is not applicable to PAN-OS.

What Eclypsium reported, and how the vendor framed it

SecurityWeek’s January 24, 2025 report relayed Eclypsium’s hardware observations and Palo Alto Networks’ response. The distinction matters: Eclypsium reported findings from appliances it examined, while the vendor assessed whether the issues were exploitable or applicable in its products and under PAN-OS conditions.

  • Reported privilege path: SecurityWeek said Eclypsium raised the possibility of chaining CVE-2024-0012 and CVE-2024-9474 to reach the privileges needed for BootHole. This is a researcher concern as reported by the outlet, not a vendor-confirmed exploitation path.
  • PA-415 SPI flash access: SecurityWeek reported a concern involving access controls for SPI flash on the PA-415. Palo Alto Networks responded, as quoted by the outlet, that exploitation requires physical access and hardware tampering, and recommended restricting physical access.
  • Overall product assessment: SecurityWeek reported that Palo Alto Networks considered many of the issues difficult to exploit under normal conditions or inapplicable to its products.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Can these BIOS vulnerabilities be exploited remotely?

The vendor’s bulletin does not characterize the listed exploitable firmware issues as unauthenticated remote vulnerabilities. It says exploitation requires prior PAN-OS compromise with root Linux privileges or physical access to open the device. That is the vendor’s assessment, not a claim that every possible attack chain has been ruled out. Eclypsium’s proposed privilege chain, as relayed by SecurityWeek, should be kept separate from the bulletin’s stated prerequisites.

What administrators should do

  1. Check the current vendor bulletin: Review PAN-SA-2025-0003 for any revisions after June 24, 2025, particularly for firmware status on the specified InsydeH2O issues.
  2. Run supported, current PAN-OS: Apply the appropriate current release for your appliance and maintenance plan. The bulletin lists PAN-OS 10.2.14 and 11.1.8 as fixes for BootHole; those historical fixed-version entries should not substitute for checking current supported releases.
  3. Restrict management access: Palo Alto Networks recommends limiting access to the management web interface to trusted internal IP addresses and following its management-interface best practices.
  4. Protect physical access: Limit who can reach and open the appliance, particularly in light of the PA-415 SPI flash concern and the vendor’s stated physical-access prerequisite.

Palo Alto Networks said in the bulletin’s June 24, 2025 update: “Palo Alto Networks is not aware of any malicious exploitation of these issues in our products.” This is the vendor’s awareness statement as of that update, not an independently verified assessment of activity after that date.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.