imPC@ndo IT

Palo Alto vulnerabilities

371 CVE

CVE-2016-3655
Critical 9.8

The management web interface in Palo Alto Networks PAN-OS before 5.0.18, 6.0.x before 6.0.13, 6.1.x before 6.1.10, and 7.0.x before 7.0.5 allows remote attackers to execute arbitrary OS commands via an unspecified API call.

paloaltonetworks pan-os
0.03EPSS
CVE-2012-6600
High 9.0

The device-management command-line interface in Palo Alto Networks PAN-OS 4.0.x before 4.0.9 and 4.1.x before 4.1.2 allows remote authenticated users to execute arbitrary commands via unspecified vectors, aka Ref ID 34502.

paloaltonetworks pan-os
0.03EPSS
CVE-2012-6602
High 9.0

The device-management command-line interface in Palo Alto Networks PAN-OS before 3.1.10 and 4.0.x before 4.0.4 allows remote authenticated users to execute arbitrary commands via unspecified vectors, aka Ref ID 30122.

paloaltonetworks pan-os
0.03EPSS
CVE-2012-6599
High 9.0

The device-management command-line interface in Palo Alto Networks PAN-OS 4.0.x before 4.0.8 and 4.1.x before 4.1.1 allows remote authenticated users to execute arbitrary commands via unspecified vectors, aka Ref ID 33476.

paloaltonetworks pan-os
0.03EPSS
CVE-2012-6598
High 9.0

The device-management command-line interface in Palo Alto Networks PAN-OS 4.0.x before 4.0.8 allows remote authenticated users to execute arbitrary commands via unspecified vectors, aka Ref ID 33080.

paloaltonetworks pan-os
0.03EPSS
CVE-2012-6595
High 9.0

The device-management command-line interface in Palo Alto Networks PAN-OS 4.0.x before 4.0.9 and 4.1.x before 4.1.2 allows remote authenticated administrators to execute arbitrary commands via unspecified vectors, aka Ref ID 34595.

paloaltonetworks pan-os
0.03EPSS
CVE-2012-6594
High 9.0

The device-management command-line interface in Palo Alto Networks PAN-OS before 3.1.11, 4.0.x before 4.0.8, and 4.1.x before 4.1.1 allows remote authenticated administrators to execute arbitrary commands via unspecified vectors, aka Ref ID 34299.

paloaltonetworks pan-os
0.03EPSS
CVE-2012-6591
High 9.0

The device-management command-line interface in Palo Alto Networks PAN-OS before 3.1.10 and 4.0.x before 4.0.5 allows remote authenticated administrators to execute arbitrary commands via unspecified vectors, aka Ref ID 31116.

paloaltonetworks pan-os
0.03EPSS
CVE-2015-6531
High 7.8

Palo Alto Networks Panorama VM Appliance with PAN-OS before 6.0.1 might allow remote attackers to execute arbitrary Python code via a crafted firmware image file.

paloaltonetworks pan-os
0.03EPSS
CVE-2013-5663
Medium 4.3

The App-ID cache feature in Palo Alto Networks PAN-OS before 4.0.14, 4.1.x before 4.1.11, and 5.0.x before 5.0.2 allows remote attackers to bypass intended security policies via crafted requests that trigger invalid caching, as demonstrated by incorrect identi…

paloaltonetworks pan-os
0.03EPSS
CVE-2020-2008
High 7.2

An OS command injection and external control of filename vulnerability in Palo Alto Networks PAN-OS allows authenticated administrators to execute code with root privileges or delete arbitrary system files and impact the system's integrity or cause a denial of…

paloaltonetworks pan-os
0.03EPSS
CVE-2020-2014
High 8.8

An OS Command Injection vulnerability in PAN-OS management server allows authenticated users to inject and execute arbitrary shell commands with root privileges. This issue affects: All versions of PAN-OS 7.1 and 8.0; PAN-OS 8.1 versions earlier than 8.1.14; P…

paloaltonetworks pan-os
0.03EPSS
CVE-2016-3654
High 7.2

The device management command line interface (CLI) in Palo Alto Networks PAN-OS before 5.0.18, 5.1.x before 5.1.11, 6.0.x before 6.0.13, 6.1.x before 6.1.10, and 7.0.x before 7.0.5H2 allows remote authenticated administrators to execute arbitrary OS commands v…

paloaltonetworks pan-os
0.03EPSS
CVE-2020-2030
High 7.2

An OS Command Injection vulnerability in the PAN-OS management interface that allows authenticated administrators to execute arbitrary OS commands with root privileges. This issue impacts PAN-OS 8.1 versions earlier than PAN-OS 8.1.15; and all versions of PAN-…

paloaltonetworks pan-os
0.03EPSS
CVE-2019-1572
High 7.5

PAN-OS 9.0.0 may allow an unauthenticated remote user to access php files.

paloaltonetworks pan-os
0.02EPSS
CVE-2017-9458
Critical 9.8

XML external entity (XXE) vulnerability in the GlobalProtect internal and external gateway interface in Palo Alto Networks PAN-OS before 6.1.18, 7.0.x before 7.0.17, 7.1.x before 7.1.12, and 8.0.x before 8.0.3 allows remote attackers to obtain sensitive inform…

paloaltonetworks pan-os
0.02EPSS
CVE-2017-17841
Medium 5.9

Palo Alto Networks PAN-OS 6.1, 7.1, and 8.0.x before 8.0.7, when an interface implements SSL decryption with RSA enabled or hosts a GlobalProtect portal or gateway, might allow remote attackers to decrypt TLS ciphertext data by leveraging a Bleichenbacher RSA …

paloaltonetworks pan-os
0.02EPSS
CVE-2020-2042
High 7.2

A buffer overflow vulnerability in the PAN-OS management web interface allows authenticated administrators to disrupt system processes and potentially execute arbitrary code with root privileges. This issue impacts only PAN-OS 10.0 versions earlier than PAN-OS…

paloaltonetworks pan-os
0.02EPSS
CVE-2013-5664
Medium 4.3

Cross-site scripting (XSS) vulnerability in the web-based device-management API browser in Palo Alto Networks PAN-OS before 4.1.13 and 5.0.x before 5.0.6 allows remote attackers to inject arbitrary web script or HTML via crafted data, aka Ref ID 50908.

paloaltonetworks pan-os
0.02EPSS
CVE-2020-2010
High 7.2

An OS command injection vulnerability in PAN-OS management interface allows an authenticated administrator to execute arbitrary OS commands with root privileges. This issue affects: All versions of PAN-OS 7.1 and 8.0; PAN-OS 8.1 versions earlier than 8.1.14; P…

paloaltonetworks pan-os
0.02EPSS
CVE-2020-2007
High 7.2

An OS command injection vulnerability in the management server component of PAN-OS allows an authenticated user to potentially execute arbitrary commands with root privileges. This issue affects: All PAN-OS 7.1 versions; PAN-OS 8.1 versions earlier than 8.1.14…

paloaltonetworks pan-os
0.02EPSS
CVE-2017-15942
High 7.5

Palo Alto Networks PAN-OS before 6.1.19, 7.0.x before 7.0.19, 7.1.x before 7.1.13, and 8.0.x before 8.0.6 allows remote attackers to cause a denial of service via vectors related to the management interface.

paloaltonetworks pan-os
0.02EPSS
CVE-2018-10142
High 7.5

The Expedition Migration tool 1.0.106 and earlier may allow an unauthenticated attacker to enumerate files on the operating system.

paloaltonetworks expedition
0.02EPSS
CVE-2020-2041
High 7.5

An insecure configuration of the appweb daemon of Palo Alto Networks PAN-OS 8.1 allows a remote unauthenticated user to send a specifically crafted request to the device that causes the appweb service to crash. Repeated attempts to send this request result in …

paloaltonetworks pan-os
0.02EPSS
CVE-2020-2027
High 7.2

A buffer overflow vulnerability in the authd component of the PAN-OS management server allows authenticated administrators to disrupt system processes and potentially execute arbitrary code with root privileges. This issue affects: All versions of PAN-OS 7.1 a…

paloaltonetworks pan-os
0.02EPSS