imPC@ndo IT

Palo Alto vulnerabilities

371 CVE

CVE-2021-3056
High 8.8

A memory corruption vulnerability in Palo Alto Networks PAN-OS GlobalProtect Clientless VPN enables an authenticated attacker to execute arbitrary code with root user privileges during SAML authentication. This issue impacts: PAN-OS 8.1 versions earlier than P…

paloaltonetworks pan-os
0.01EPSS
CVE-2024-5921
High 8.8

An insufficient certification validation issue in the Palo Alto Networks GlobalProtect app enables attackers to connect the GlobalProtect app to arbitrary servers. This can enable a local non-administrative operating system user or an attacker on the same subn…

paloaltonetworks globalprotect
0.01EPSS
CVE-2021-3057
High 8.1

A stack-based buffer overflow vulnerability exists in the Palo Alto Networks GlobalProtect app that enables a man-in-the-middle attacker to disrupt system processes and potentially execute arbitrary code with SYSTEM privileges. This issue impacts: GlobalProtec…

paloaltonetworks globalprotect
0.01EPSS
CVE-2024-8686
High 7.2

A command injection vulnerability in Palo Alto Networks PAN-OS software enables an authenticated administrator to bypass system restrictions and run arbitrary commands as root on the firewall.

paloaltonetworks pan-os
0.01EPSS
CVE-2021-3044
Critical 9.8

An improper authorization vulnerability in Palo Alto Networks Cortex XSOAR enables a remote unauthenticated attacker with network access to the Cortex XSOAR server to perform unauthorized actions through the REST API. This issue impacts: Cortex XSOAR 6.1.0 bui…

paloaltonetworks cortex_xsoar
0.01EPSS
CVE-2026-0261
High 7.2

Multiple command injection vulnerabilities in Palo Alto Networks PAN-OS® software enable an authenticated administrator to bypass system restrictions and run arbitrary commands as a root user. To be able to exploit this issue, the user must have access to the …

paloaltonetworks pan-os · siemens ruggedcom_ape1808_firmware
0.01EPSS
CVE-2014-3764
Medium 4.3

Cross-site scripting (XSS) vulnerability in the web-based device management interface in Palo Alto Networks PAN-OS before 5.0.15, 5.1.x before 5.1.10, and 6.0.x before 6.0.6 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors…

paloaltonetworks pan-os
0.01EPSS
CVE-2026-0273
High 7.2

A command injection vulnerability in Palo Alto Networks PAN-OS® software enables an authenticated administrator to bypass system restrictions and run arbitrary commands as a root user. To be able to exploit this issue, the user must have access to the PAN-OS C…

paloaltonetworks pan-os
0.01EPSS
CVE-2020-1999
Medium 5.3

A vulnerability exists in the Palo Alto Network PAN-OS signature-based threat detection engine that allows an attacker to communicate with devices in the network in a way that is not analyzed for threats by sending data through specifically crafted TCP packets…

paloaltonetworks pan-os
0.01EPSS
CVE-2020-2001
High 8.1

An external control of path and data vulnerability in the Palo Alto Networks PAN-OS Panorama XSLT processing logic that allows an unauthenticated user with network access to PAN-OS management interface to write attacker supplied file on the system and elevate …

paloaltonetworks pan-os
0.01EPSS
CVE-2020-2018
Critical 9.0

An authentication bypass vulnerability in the Panorama context switching feature allows an attacker with network access to a Panorama's management interface to gain privileged access to managed firewalls. An attacker requires some knowledge of managed firewall…

paloaltonetworks pan-os
0.01EPSS
CVE-2012-6597
Medium 6.3

Palo Alto Networks PAN-OS before 3.1.11 and 4.0.x before 4.0.9 allows remote authenticated users to cause a denial of service (management-server crash) by using the command-line interface for a crafted command, aka Ref ID 35254.

paloaltonetworks pan-os
0.01EPSS
CVE-2023-0003
Medium 6.5

A file disclosure vulnerability in the Palo Alto Networks Cortex XSOAR server software enables an authenticated user with access to the web interface to read local files from the server.

fedoraproject fedora · paloaltonetworks cortex_xsoar
0.01EPSS
CVE-2012-6596
Medium 5.0

Palo Alto Networks PAN-OS 4.0.x before 4.0.9 and 4.1.x before 4.1.3 stores cleartext LDAP bind passwords in authd.log, which allows context-dependent attackers to obtain sensitive information by reading this file, aka Ref ID 35493.

paloaltonetworks pan-os
0.01EPSS
CVE-2020-2002
High 8.1

An authentication bypass by spoofing vulnerability exists in the authentication daemon and User-ID components of Palo Alto Networks PAN-OS by failing to verify the integrity of the Kerberos key distribution center (KDC) before authenticating users. This affect…

paloaltonetworks pan-os
0.01EPSS
CVE-2021-3040
Medium 6.7

An unsafe deserialization vulnerability in Bridgecrew Checkov by Prisma Cloud allows arbitrary code execution when processing a malicious terraform file. This issue impacts Checkov 2.0 versions earlier than Checkov 2.0.139. Checkov 1.0 versions are not impacte…

paloaltonetworks bridgecrew_checkov
0.01EPSS
CVE-2021-3035
Medium 6.7

An unsafe deserialization vulnerability in Bridgecrew Checkov by Prisma Cloud allows arbitrary code execution when processing a malicious terraform file. This issue impacts Checkov 2.0 versions earlier than Checkov 2.0.26. Checkov 1.0 versions are not impacted…

paloaltonetworks bridgecrew_checkov
0.01EPSS
CVE-2024-5914
Critical 9.8

A command injection issue in Palo Alto Networks Cortex XSOAR CommonScripts Pack allows an unauthenticated attacker to execute arbitrary commands within the context of an integration container.

paloaltonetworks cortex_xsoar_commonscripts
0.01EPSS
CVE-2020-2022
High 7.5

An information exposure vulnerability exists in Palo Alto Networks Panorama software that discloses the token for the Panorama web interface administrator's session to a managed device when the Panorama administrator performs a context switch into that device.…

paloaltonetworks pan-os
0.01EPSS
CVE-2021-3033
Critical 9.1

An improper verification of cryptographic signature vulnerability exists in the Palo Alto Networks Prisma Cloud Compute console. This vulnerability enables an attacker to bypass signature validation during SAML authentication by logging in to the Prisma Cloud …

paloaltonetworks prisma_cloud
0.01EPSS
CVE-2016-9151
High 7.8

Palo Alto Networks PAN-OS before 5.0.20, 5.1.x before 5.1.13, 6.0.x before 6.0.15, 6.1.x before 6.1.15, 7.0.x before 7.0.11, and 7.1.x before 7.1.6 allows local users to gain privileges via crafted values of unspecified environment variables.

paloaltonetworks pan-os
0.01EPSS
CVE-2017-7216
Medium 6.5

The Management Web Interface in Palo Alto Networks PAN-OS before 7.1.9 allows remote authenticated users to obtain sensitive information via unspecified request parameters.

paloaltonetworks pan-os
0.01EPSS
CVE-2017-15941
Medium 6.1

Cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS before 6.1.19, 7.0.x before 7.0.19, 7.1.x before 7.1.14, and 8.0.x before 8.0.7, when the GlobalProtect gateway or portal is configured, allows remote attackers to inject arbitrary web scrip…

paloaltonetworks pan-os
0.01EPSS
CVE-2017-12416
Medium 6.1

Cross-site scripting (XSS) vulnerability in the GlobalProtect internal and external gateway interface in Palo Alto Networks PAN-OS before 6.1.18, 7.0.x before 7.0.17, 7.1.x before 7.1.12, and 8.0.x before 8.0.3 allows remote attackers to inject arbitrary web s…

paloaltonetworks pan-os
0.01EPSS
CVE-2017-9467
Medium 6.1

Cross-site scripting (XSS) vulnerability in the GlobalProtect external interface in Palo Alto Networks PAN-OS before 6.1.18, 7.x before 7.0.16, 7.1.x before 7.1.11, and 8.x before 8.0.3 allows remote attackers to inject arbitrary web script or HTML via unspeci…

paloaltonetworks pan-os
0.01EPSS