imPC@ndo IT

Palo Alto vulnerabilities

371 CVE

CVE-2024-9471
Medium 4.7

A privilege escalation (PE) vulnerability in the XML API of Palo Alto Networks PAN-OS software enables an authenticated PAN-OS administrator with restricted privileges to use a compromised XML API key to perform actions as a higher privileged PAN-OS administra…

paloaltonetworks pan-os
0.00EPSS
CVE-2019-17435
Medium 5.5

A Local Privilege Escalation vulnerability exists in the GlobalProtect Agent for Windows 5.0.3 and earlier, and GlobalProtect Agent for Windows 4.1.12 and earlier, in which the auto-update feature can allow for modification of a GlobalProtect Agent MSI install…

paloaltonetworks globalprotect
0.00EPSS
CVE-2024-5920
Medium 4.8

A cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS software enables an authenticated read-write Panorama administrator to push a specially crafted configuration to a PAN-OS node. This enables impersonation of a legitimate PAN-OS administra…

paloaltonetworks pan-os
0.00EPSS
CVE-2023-0002
Medium 5.5

A problem with a protection mechanism in the Palo Alto Networks Cortex XDR agent on Windows devices allows a local user to execute privileged cytool commands that disable or uninstall the agent.

paloaltonetworks cortex_xdr_agent
0.00EPSS
CVE-2024-9473
High 7.8

A privilege escalation vulnerability in the Palo Alto Networks GlobalProtect app on Windows allows a locally authenticated non-administrative Windows user to escalate their privileges to NT AUTHORITY/SYSTEM through the use of the repair functionality offered b…

paloaltonetworks globalprotect
0.00EPSS
CVE-2026-0274
Critical 9.1

An improper validation of credentials vulnerability in the CommvaultSecurityIQ integration for Cortex XSOAR and Cortex XSIAM allows an unauthenticated attacker to access and modify protected resources.

paloaltonetworks cortex_xsiam_commvaultsecurityiq_marketplace · paloaltonetworks cortex_xsoar_commvaultsecurityiq_marketplace
0.00EPSS
CVE-2026-0284
Critical 9.9

An XML injection vulnerability in the Large Scale VPN (LSVPN) functionality of Palo Alto Networks PAN-OS® software enables an unauthenticated attacker with network access to inject malicious XML content, potentially leading to information disclosure or corrupt…

paloaltonetworks pan-os
0.00EPSS
CVE-2020-1976
Medium 4.7

A denial-of-service (DoS) vulnerability in Palo Alto Networks GlobalProtect software running on Mac OS allows authenticated local users to cause the Mac OS kernel to hang or crash. This issue affects GlobalProtect 5.0.5 and earlier versions of GlobalProtect 5.…

paloaltonetworks globalprotect
0.00EPSS
CVE-2020-1991
High 7.8

An insecure temporary file vulnerability in Palo Alto Networks Traps allows a local authenticated Windows user to escalate privileges or overwrite system files. This issue affects Palo Alto Networks Traps 5.0 versions before 5.0.8; 6.1 versions before 6.1.4 on…

paloaltonetworks traps
0.00EPSS
CVE-2022-0017
High 7.0

An improper link resolution before file access ('link following') vulnerability exists in the Palo Alto Networks GlobalProtect app on Windows that enables a local attacker to disrupt system processes and potentially execute arbitrary code with SYSTEM privilege…

paloaltonetworks globalprotect
0.00EPSS
CVE-2019-1573
Low 2.5

GlobalProtect Agent 4.1.0 for Windows and GlobalProtect Agent 4.1.10 and earlier for macOS may allow a local authenticated attacker who has compromised the end-user account and gained the ability to inspect memory, to access authentication and/or session token…

paloaltonetworks globalprotect
0.00EPSS
CVE-2020-1989
High 7.0

An incorrect privilege assignment vulnerability when writing application-specific files in the Palo Alto Networks Global Protect Agent for Linux on ARM platform allows a local authenticated user to gain root privileges on the system. This issue affects Palo Al…

paloaltonetworks globalprotect
0.00EPSS
CVE-2023-0005
Medium 4.1

A vulnerability in Palo Alto Networks PAN-OS software enables an authenticated administrator to expose the plaintext values of secrets stored in the device configuration and encrypted API keys.

paloaltonetworks pan-os
0.00EPSS
CVE-2026-0272
High 7.2

A privilege escalation vulnerability in Palo Alto Networks PAN-OS® software allows an authenticated administrator with access to the Command Line Interface (CLI) to perform actions on the device with root privileges. The security risk posed by this issue is…

paloaltonetworks pan-os
0.00EPSS
CVE-2020-1986
Medium 5.5

Improper input validation vulnerability in Secdo allows an authenticated local user with 'create folders or append data' access to the root of the OS disk (C:\) to cause a system crash on every login. This issue affects all versions Secdo for Windows.

paloaltonetworks secdo
0.00EPSS
CVE-2020-1985
High 7.8

Incorrect Default Permissions on C:\Programdata\Secdo\Logs folder in Secdo allows local authenticated users to overwrite system files and gain escalated privileges. This issue affects all versions Secdo for Windows.

paloaltonetworks secdo
0.00EPSS
CVE-2021-3037
Low 2.3

An information exposure through log file vulnerability exists in Palo Alto Networks PAN-OS software where the connection details for a scheduled configuration export are logged in system logs. Logged information includes the cleartext username, password, and I…

paloaltonetworks pan-os
0.00EPSS
CVE-2022-0014
Medium 6.7

An untrusted search path vulnerability exists in the Palo Alto Networks Cortex XDR agent that enables a local attacker with file creation privilege in the Windows root directory (such as C:\) to store a program that can then be unintentionally executed by anot…

paloaltonetworks cortex_xdr_agent
0.00EPSS
CVE-2024-5916
Medium 4.4

An information exposure vulnerability in Palo Alto Networks PAN-OS software enables a local system administrator to unintentionally disclose secrets, passwords, and tokens of external systems. A read-only administrator who has access to the config log, can rea…

paloaltonetworks pan-os
0.00EPSS
CVE-2021-3042
High 7.8

A local privilege escalation (PE) vulnerability exists in the Palo Alto Networks Cortex XDR agent on Windows platforms that enables an authenticated local Windows user to execute programs with SYSTEM privileges. Exploiting this vulnerability requires the user …

paloaltonetworks cortex_xdr_agent
0.00EPSS
CVE-2021-3041
High 7.8

A local privilege escalation vulnerability exists in the Palo Alto Networks Cortex XDR agent on Windows platforms that enables an authenticated local Windows user to execute programs with SYSTEM privileges. This requires the user to have the privilege to creat…

paloaltonetworks cortex_xdr_agent
0.00EPSS
CVE-2021-3036
Medium 4.4

An information exposure through log file vulnerability exists in Palo Alto Networks PAN-OS software where secrets in PAN-OS XML API requests are logged in cleartext to the web server logs when the API is used incorrectly. This vulnerability applies only to PAN…

paloaltonetworks pan-os
0.00EPSS
CVE-2024-5906
Medium 4.8

A cross-site scripting (XSS) vulnerability in Palo Alto Networks Prisma Cloud Compute software enables a malicious administrator with add/edit permissions for identity providers to store a JavaScript payload using the web interface on Prisma Cloud Compute. Thi…

paloaltonetworks prisma_cloud
0.00EPSS
CVE-2022-0012
Medium 6.1

An improper link resolution before file access vulnerability exists in the Palo Alto Networks Cortex XDR agent on Windows platforms that enables a local user to delete arbitrary system files and impact the system integrity or cause a denial of service conditio…

paloaltonetworks cortex_xdr_agent
0.00EPSS
CVE-2026-0240
High 8.7

An information disclosure vulnerability in Trust Protection Foundation enables an authenticated attacker to obtain sensitive information from the server's vault. Successful exploitation of this issue allows the attacker to impersonate any user within the envir…

paloaltonetworks trust_protection_foundation
0.00EPSS