imPC@ndo IT

Palo Alto vulnerabilities

371 CVE

CVE-2024-3400
Ransomware Critical 10.0

A command injection as a result of arbitrary file creation vulnerability in the GlobalProtect feature of Palo Alto Networks PAN-OS software for specific PAN-OS versions and distinct feature configurations may enable an unauthenticated attacker to execute arbit…

paloaltonetworks pan-os
1.00EPSS
CVE-2024-0012
Ransomware Critical 9.8

An authentication bypass in Palo Alto Networks PAN-OS software enables an unauthenticated attacker with network access to the management web interface to gain PAN-OS administrator privileges to perform administrative actions, tamper with the configuration, or …

paloaltonetworks pan-os
1.00EPSS
CVE-2024-9465
Exploited Critical 9.1

An SQL injection vulnerability in Palo Alto Networks Expedition allows an unauthenticated attacker to reveal Expedition database contents, such as password hashes, usernames, device configurations, and device API keys. With this, attackers can also create and …

paloaltonetworks expedition
1.00EPSS
CVE-2024-9463
Exploited High 7.5

An OS command injection vulnerability in Palo Alto Networks Expedition allows an unauthenticated attacker to run arbitrary OS commands as root in Expedition, resulting in disclosure of usernames, cleartext passwords, device configurations, and device API keys …

paloaltonetworks expedition
0.98EPSS
CVE-2025-0108
Exploited Critical 9.1

An authentication bypass in the Palo Alto Networks PAN-OS software enables an unauthenticated attacker with network access to the management web interface to bypass the authentication otherwise required by the PAN-OS management web interface and invoke certain…

paloaltonetworks pan-os
0.98EPSS
CVE-2017-15944
Exploited Critical 9.8

Palo Alto Networks PAN-OS before 6.1.19, 7.0.x before 7.0.19, 7.1.x before 7.1.14, and 8.0.x before 8.0.6 allows remote attackers to execute arbitrary code via vectors involving the management interface.

paloaltonetworks pan-os
0.98EPSS
CVE-2024-9474
Ransomware High 7.2

A privilege escalation vulnerability in Palo Alto Networks PAN-OS software allows a PAN-OS administrator with access to the management web interface to perform actions on the firewall with root privileges. Cloud NGFW and Prisma Access are not impacted by this…

paloaltonetworks pan-os
0.95EPSS
CVE-2026-0257
Ransomware Critical 9.1

Authentication bypass vulnerabilities in the GlobalProtect portal and gateway of Palo Alto Networks PAN-OS® software allows the attacker to bypass security restrictions and establish an unauthorized VPN connection. Panorama and Cloud NGFW are not impacted by …

paloaltonetworks pan-os · paloaltonetworks prisma_access · siemens ruggedcom_ape1808_firmware
0.94EPSS
CVE-2024-5910
Exploited Critical 9.8

Missing authentication for a critical function in Palo Alto Networks Expedition can lead to an Expedition admin account takeover for attackers with network access to Expedition. Note: Expedition is a tool aiding in configuration migration, tuning, and enrichm…

paloaltonetworks expedition
0.92EPSS
CVE-2016-5195
Exploited High 7.0

Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by leveraging incorrect handling of a copy-on-write (COW) feature to write to a read-only memory mapping, as exploited in the wild in October 2016…

canonical ubuntu_linux · debian debian_linux · fedoraproject fedora · linux linux_kernel · and 14 more
0.84EPSS
CVE-2019-1579
Ransomware High 8.1

Remote Code Execution in PAN-OS 7.1.18 and earlier, PAN-OS 8.0.11-h1 and earlier, and PAN-OS 8.1.2 and earlier with GlobalProtect Portal or GlobalProtect Gateway Interface enabled may allow an unauthenticated remote attacker to execute arbitrary code.

paloaltonetworks pan-os
0.46EPSS
CVE-2026-0300
Exploited Critical 9.8

A buffer overflow vulnerability in the User-ID™ Authentication Portal (aka Captive Portal) service of Palo Alto Networks PAN-OS software allows an unauthenticated attacker to execute arbitrary code with root privileges on the PA-Series and VM-Series firewalls …

paloaltonetworks pan-os · siemens ruggedcom_ape1808_firmware
0.32EPSS
CVE-2024-3393
Exploited High 7.5

A Denial of Service vulnerability in the DNS Security feature of Palo Alto Networks PAN-OS software allows an unauthenticated attacker to send a malicious packet through the data plane of the firewall that reboots the firewall. Repeated attempts to trigger thi…

paloaltonetworks pan-os · paloaltonetworks prisma_access
0.29EPSS
CVE-2018-14634
Exploited High 7.8

An integer overflow flaw was found in the Linux kernel's create_elf_tables() function. An unprivileged local user with access to SUID (or otherwise privileged) binary could use this flaw to escalate their privileges on the system. Kernel versions 2.6.x, 3.10.x…

canonical ubuntu_linux · f5 big-ip_access_policy_manager · f5 big-ip_advanced_firewall_manager · f5 big-ip_analytics · and 24 more
0.15EPSS
CVE-2020-2021
Ransomware Critical 10.0

When Security Assertion Markup Language (SAML) authentication is enabled and the 'Validate Identity Provider Certificate' option is disabled (unchecked), improper verification of signatures in PAN-OS SAML authentication enables an unauthenticated network-based…

paloaltonetworks pan-os
0.04EPSS
CVE-2022-0028
Exploited High 8.6

A PAN-OS URL filtering policy misconfiguration could allow a network-based attacker to conduct reflected and amplified TCP denial-of-service (RDoS) attacks. The DoS attack would appear to originate from a Palo Alto Networks PA-Series (hardware), VM-Series (vir…

paloaltonetworks pan-os
0.02EPSS
CVE-2025-0111
Exploited Medium 6.5

An authenticated file read vulnerability in the Palo Alto Networks PAN-OS software enables an authenticated attacker with network access to the management web interface to read files on the PAN-OS filesystem that are readable by the “nobody” user. You can gre…

paloaltonetworks pan-os
0.02EPSS
CVE-2020-2038
High 7.2

An OS Command Injection vulnerability in the PAN-OS management interface that allows authenticated administrators to execute arbitrary OS commands with root privileges. This issue impacts: PAN-OS 9.0 versions earlier than 9.0.10; PAN-OS 9.1 versions earlier th…

paloaltonetworks pan-os
0.86EPSS
CVE-2024-9464
Medium 6.5

An OS command injection vulnerability in Palo Alto Networks Expedition allows an authenticated attacker to run arbitrary OS commands as root in Expedition, resulting in disclosure of usernames, cleartext passwords, device configurations, and device API keys of…

paloaltonetworks expedition
0.82EPSS
CVE-2025-0107
Critical 9.8

An OS command injection vulnerability in Palo Alto Networks Expedition enables an unauthenticated attacker to run arbitrary OS commands as the www-data user in Expedition, which results in the disclosure of usernames, cleartext passwords, device configurations…

paloaltonetworks expedition
0.79EPSS
CVE-2020-2039
Medium 5.3

An uncontrolled resource consumption vulnerability in Palo Alto Networks PAN-OS allows for a remote unauthenticated user to upload temporary files through the management web interface that are not properly deleted after the request is finished. It is possible …

paloaltonetworks pan-os
0.46EPSS
CVE-2016-4971
High 8.8

GNU wget before 1.18 allows remote servers to write to arbitrary files by redirecting a request from HTTP to a crafted FTP resource.

canonical ubuntu_linux · gnu wget · oracle solaris · paloaltonetworks pan-os
0.46EPSS
CVE-2016-8610
High 7.5

A denial of service flaw was found in OpenSSL 0.9.8, 1.0.1, 1.0.2 through 1.0.2h, and 1.1.0 in the way the TLS/SSL protocol defined processing of ALERT packets during a connection handshake. A remote attacker could use this flaw to make a TLS/SSL server consum…

debian debian_linux · fujitsu m10-1_firmware · fujitsu m10-4_firmware · fujitsu m10-4s_firmware · and 41 more
0.40EPSS
CVE-2016-9150
Critical 9.8

Buffer overflow in the management web interface in Palo Alto Networks PAN-OS before 5.0.20, 5.1.x before 5.1.13, 6.0.x before 6.0.15, 6.1.x before 6.1.15, 7.0.x before 7.0.11, and 7.1.x before 7.1.6 allows remote attackers to execute arbitrary code via unspeci…

paloaltonetworks pan-os
0.35EPSS
CVE-2021-3060
High 8.1

An OS command injection vulnerability in the Simple Certificate Enrollment Protocol (SCEP) feature of PAN-OS software allows an unauthenticated network-based attacker with specific knowledge of the firewall configuration to execute arbitrary code with root use…

paloaltonetworks pan-os · paloaltonetworks prisma_access
0.34EPSS