imPC@ndo IT

Palo Alto vulnerabilities

371 CVE

CVE-2021-3045
Medium 4.9

An OS command argument injection vulnerability in the Palo Alto Networks PAN-OS web interface enables an authenticated administrator to read any arbitrary file from the file system. This issue impacts: PAN-OS 8.1 versions earlier than PAN-OS 8.1.19; PAN-OS 9.0…

paloaltonetworks pan-os
0.01EPSS
CVE-2016-2219
Medium 5.4

Cross-site scripting (XSS) vulnerability in the management interface in Palo Alto Networks PAN-OS 7.x before 7.0.8 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

paloaltonetworks pan-os
0.01EPSS
CVE-2020-2035
Low 3.0

When SSL/TLS Forward Proxy Decryption mode has been configured to decrypt the web transactions, the PAN-OS URL filtering feature inspects the HTTP Host and URL path headers for policy enforcement on the decrypted HTTPS web transactions but does not consider Se…

paloaltonetworks pan-os
0.01EPSS
CVE-2012-6606
Medium 5.8

Palo Alto Networks GlobalProtect before 1.1.7, and NetConnect, does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof portal servers and obtain sensitive information via a crafted certificate.

paloaltonetworks globalprotect · paloaltonetworks netconnect
0.01EPSS
CVE-2020-2033
Medium 5.3

When the pre-logon feature is enabled, a missing certification validation in Palo Alto Networks GlobalProtect app can disclose the pre-logon authentication cookie to a man-in-the-middle attacker on the same local area network segment with the ability to manipu…

paloaltonetworks globalprotect
0.01EPSS
CVE-2022-0018
Medium 6.1

An information exposure vulnerability exists in the Palo Alto Networks GlobalProtect app on Windows and MacOS where the credentials of the local user account are sent to the GlobalProtect portal when the Single Sign-On feature is enabled in the GlobalProtect p…

paloaltonetworks globalprotect
0.01EPSS
CVE-2025-4615
High 7.2

An improper input neutralization vulnerability in the management web interface of the Palo Alto Networks PAN-OS® software enables an authenticated administrator to bypass system restrictions and execute arbitrary commands. The security risk posed by this issu…

paloaltonetworks pan-os
0.01EPSS
CVE-2020-2044
Low 3.3

An information exposure through log file vulnerability where an administrator's password or other sensitive information may be logged in cleartext while using the CLI in Palo Alto Networks PAN-OS software. The opcmdhistory.log file was introduced to track oper…

paloaltonetworks pan-os
0.01EPSS
CVE-2020-2043
Low 3.3

An information exposure through log file vulnerability where sensitive fields are recorded in the configuration log without masking on Palo Alto Networks PAN-OS software when the after-change-detail custom syslog field is enabled for configuration logs and the…

paloaltonetworks pan-os
0.01EPSS
CVE-2022-0023
Medium 5.9

An improper handling of exceptional conditions vulnerability exists in the DNS proxy feature of Palo Alto Networks PAN-OS software that enables a meddler-in-the-middle (MITM) to send specifically crafted traffic to the firewall that causes the service to resta…

paloaltonetworks pan-os
0.01EPSS
CVE-2021-3062
High 8.1

An improper access control vulnerability in PAN-OS software enables an attacker with authenticated access to GlobalProtect portals and gateways to connect to the EC2 instance metadata endpoint for VM-Series firewalls hosted on Amazon AWS. Exploitation of this …

paloaltonetworks pan-os
0.01EPSS
CVE-2026-0227
High 7.5

A vulnerability in Palo Alto Networks PAN-OS software enables an unauthenticated attacker to cause a denial of service (DoS) to the firewall. Repeated attempts to trigger this issue results in the firewall entering into maintenance mode.

paloaltonetworks pan-os · paloaltonetworks prisma_access
0.01EPSS
CVE-2019-1565
Medium 5.4

The PAN-OS external dynamics lists in PAN-OS 7.1.21 and earlier, PAN-OS 8.0.14 and earlier, and PAN-OS 8.1.5 and earlier, may allow an attacker that is authenticated in Next Generation Firewall with write privileges to External Dynamic List configuration to in…

paloaltonetworks pan-os
0.01EPSS
CVE-2022-0011
Medium 6.5

PAN-OS software provides options to exclude specific websites from URL category enforcement and those websites are blocked or allowed (depending on your rules) regardless of their associated URL category. This is done by creating a custom URL category list or …

paloaltonetworks pan-os · paloaltonetworks prisma_access
0.01EPSS
CVE-2023-6790
High 8.8

A DOM-Based cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS software enables a remote attacker to execute a JavaScript payload in the context of an administrator’s browser when they view a specifically crafted link to the PAN-OS web inter…

paloaltonetworks pan-os
0.01EPSS
CVE-2020-2013
High 8.3

A cleartext transmission of sensitive information vulnerability in Palo Alto Networks PAN-OS Panorama that discloses an authenticated PAN-OS administrator's PAN-OS session cookie. When an administrator issues a context switch request into a managed firewall wi…

paloaltonetworks pan-os
0.01EPSS
CVE-2021-3043
High 7.5

A reflected cross-site scripting (XSS) vulnerability exists in the Prisma Cloud Compute web console that enables a remote attacker to execute arbitrary JavaScript code in the browser-based web console while an authenticated administrator is using that web inte…

paloaltonetworks prisma_cloud
0.01EPSS
CVE-2024-9467
Medium 6.1

A reflected XSS vulnerability in Palo Alto Networks Expedition enables execution of malicious JavaScript in the context of an authenticated Expedition user's browser if that user clicks on a malicious link, allowing phishing attacks that could lead to Expediti…

paloaltonetworks expedition
0.01EPSS
CVE-2021-3052
High 8.0

A reflected cross-site scripting (XSS) vulnerability in the Palo Alto Network PAN-OS web interface enables an authenticated network-based attacker to mislead another authenticated PAN-OS administrator to click on a specially crafted link that performs arbitrar…

paloaltonetworks pan-os
0.01EPSS
CVE-2020-1980
High 7.8

A shell command injection vulnerability in the PAN-OS CLI allows a local authenticated user to escape the restricted shell and escalate privileges. This issue affects only PAN-OS 8.1 versions earlier than PAN-OS 8.1.13. This issue does not affect PAN-OS 7.1, P…

paloaltonetworks pan-os
0.01EPSS
CVE-2023-6791
Medium 4.9

A credential disclosure vulnerability in Palo Alto Networks PAN-OS software enables an authenticated read-only administrator to obtain the plaintext credentials of stored external system integrations such as LDAP, SCP, RADIUS, TACACS+, and SNMP from the web in…

paloaltonetworks pan-os
0.01EPSS
CVE-2019-1574
Medium 5.4

Cross-site scripting (XSS) vulnerability in Palo Alto Networks Expedition Migration tool 1.1.12 and earlier may allow an authenticated attacker to run arbitrary JavaScript or HTML in the Devices View.

paloaltonetworks expedition_migration_tool
0.01EPSS
CVE-2025-0103
High 8.8

An SQL injection vulnerability in Palo Alto Networks Expedition enables an authenticated attacker to reveal Expedition database contents, such as password hashes, usernames, device configurations, and device API keys. This vulnerability also enables attackers …

paloaltonetworks expedition
0.01EPSS
CVE-2019-1567
Medium 5.4

The Expedition Migration tool 1.1.6 and earlier may allow an authenticated attacker to run arbitrary JavaScript or HTML in the User Mapping Settings.

paloaltonetworks expedition_migration_tool
0.01EPSS
CVE-2021-3051
High 8.1

An improper verification of cryptographic signature vulnerability exists in Cortex XSOAR SAML authentication that enables an unauthenticated network-based attacker with specific knowledge of the Cortex XSOAR instance to access protected resources and perform u…

paloaltonetworks cortex_xsoar
0.01EPSS