imPC@ndo EN

Vulnerabilità Palo Alto

371 CVE

CVE-2024-3400
Ransomware Critica 10.0

A command injection as a result of arbitrary file creation vulnerability in the GlobalProtect feature of Palo Alto Networks PAN-OS software for specific PAN-OS versions and distinct feature configurations may enable an unauthenticated attacker to execute arbit…

paloaltonetworks pan-os
1.00EPSS
CVE-2024-0012
Ransomware Critica 9.8

An authentication bypass in Palo Alto Networks PAN-OS software enables an unauthenticated attacker with network access to the management web interface to gain PAN-OS administrator privileges to perform administrative actions, tamper with the configuration, or …

paloaltonetworks pan-os
1.00EPSS
CVE-2024-9465
Sfruttata Critica 9.1

An SQL injection vulnerability in Palo Alto Networks Expedition allows an unauthenticated attacker to reveal Expedition database contents, such as password hashes, usernames, device configurations, and device API keys. With this, attackers can also create and …

paloaltonetworks expedition
1.00EPSS
CVE-2024-9463
Sfruttata Alta 7.5

An OS command injection vulnerability in Palo Alto Networks Expedition allows an unauthenticated attacker to run arbitrary OS commands as root in Expedition, resulting in disclosure of usernames, cleartext passwords, device configurations, and device API keys …

paloaltonetworks expedition
0.98EPSS
CVE-2025-0108
Sfruttata Critica 9.1

An authentication bypass in the Palo Alto Networks PAN-OS software enables an unauthenticated attacker with network access to the management web interface to bypass the authentication otherwise required by the PAN-OS management web interface and invoke certain…

paloaltonetworks pan-os
0.98EPSS
CVE-2017-15944
Sfruttata Critica 9.8

Palo Alto Networks PAN-OS before 6.1.19, 7.0.x before 7.0.19, 7.1.x before 7.1.14, and 8.0.x before 8.0.6 allows remote attackers to execute arbitrary code via vectors involving the management interface.

paloaltonetworks pan-os
0.98EPSS
CVE-2024-9474
Ransomware Alta 7.2

A privilege escalation vulnerability in Palo Alto Networks PAN-OS software allows a PAN-OS administrator with access to the management web interface to perform actions on the firewall with root privileges. Cloud NGFW and Prisma Access are not impacted by this…

paloaltonetworks pan-os
0.95EPSS
CVE-2026-0257
Ransomware Critica 9.1

Authentication bypass vulnerabilities in the GlobalProtect portal and gateway of Palo Alto Networks PAN-OS® software allows the attacker to bypass security restrictions and establish an unauthorized VPN connection. Panorama and Cloud NGFW are not impacted by …

paloaltonetworks pan-os · paloaltonetworks prisma_access · siemens ruggedcom_ape1808_firmware
0.94EPSS
CVE-2024-5910
Sfruttata Critica 9.8

Missing authentication for a critical function in Palo Alto Networks Expedition can lead to an Expedition admin account takeover for attackers with network access to Expedition. Note: Expedition is a tool aiding in configuration migration, tuning, and enrichm…

paloaltonetworks expedition
0.92EPSS
CVE-2016-5195
Sfruttata Alta 7.0

Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by leveraging incorrect handling of a copy-on-write (COW) feature to write to a read-only memory mapping, as exploited in the wild in October 2016…

canonical ubuntu_linux · debian debian_linux · fedoraproject fedora · linux linux_kernel · e altri 14
0.84EPSS
CVE-2019-1579
Ransomware Alta 8.1

Remote Code Execution in PAN-OS 7.1.18 and earlier, PAN-OS 8.0.11-h1 and earlier, and PAN-OS 8.1.2 and earlier with GlobalProtect Portal or GlobalProtect Gateway Interface enabled may allow an unauthenticated remote attacker to execute arbitrary code.

paloaltonetworks pan-os
0.46EPSS
CVE-2026-0300
Sfruttata Critica 9.8

A buffer overflow vulnerability in the User-ID™ Authentication Portal (aka Captive Portal) service of Palo Alto Networks PAN-OS software allows an unauthenticated attacker to execute arbitrary code with root privileges on the PA-Series and VM-Series firewalls …

paloaltonetworks pan-os · siemens ruggedcom_ape1808_firmware
0.32EPSS
CVE-2024-3393
Sfruttata Alta 7.5

A Denial of Service vulnerability in the DNS Security feature of Palo Alto Networks PAN-OS software allows an unauthenticated attacker to send a malicious packet through the data plane of the firewall that reboots the firewall. Repeated attempts to trigger thi…

paloaltonetworks pan-os · paloaltonetworks prisma_access
0.29EPSS
CVE-2018-14634
Sfruttata Alta 7.8

An integer overflow flaw was found in the Linux kernel's create_elf_tables() function. An unprivileged local user with access to SUID (or otherwise privileged) binary could use this flaw to escalate their privileges on the system. Kernel versions 2.6.x, 3.10.x…

canonical ubuntu_linux · f5 big-ip_access_policy_manager · f5 big-ip_advanced_firewall_manager · f5 big-ip_analytics · e altri 24
0.15EPSS
CVE-2020-2021
Ransomware Critica 10.0

When Security Assertion Markup Language (SAML) authentication is enabled and the 'Validate Identity Provider Certificate' option is disabled (unchecked), improper verification of signatures in PAN-OS SAML authentication enables an unauthenticated network-based…

paloaltonetworks pan-os
0.04EPSS
CVE-2022-0028
Sfruttata Alta 8.6

A PAN-OS URL filtering policy misconfiguration could allow a network-based attacker to conduct reflected and amplified TCP denial-of-service (RDoS) attacks. The DoS attack would appear to originate from a Palo Alto Networks PA-Series (hardware), VM-Series (vir…

paloaltonetworks pan-os
0.02EPSS
CVE-2025-0111
Sfruttata Media 6.5

An authenticated file read vulnerability in the Palo Alto Networks PAN-OS software enables an authenticated attacker with network access to the management web interface to read files on the PAN-OS filesystem that are readable by the “nobody” user. You can gre…

paloaltonetworks pan-os
0.02EPSS
CVE-2020-2038
Alta 7.2

An OS Command Injection vulnerability in the PAN-OS management interface that allows authenticated administrators to execute arbitrary OS commands with root privileges. This issue impacts: PAN-OS 9.0 versions earlier than 9.0.10; PAN-OS 9.1 versions earlier th…

paloaltonetworks pan-os
0.86EPSS
CVE-2024-9464
Media 6.5

An OS command injection vulnerability in Palo Alto Networks Expedition allows an authenticated attacker to run arbitrary OS commands as root in Expedition, resulting in disclosure of usernames, cleartext passwords, device configurations, and device API keys of…

paloaltonetworks expedition
0.82EPSS
CVE-2025-0107
Critica 9.8

An OS command injection vulnerability in Palo Alto Networks Expedition enables an unauthenticated attacker to run arbitrary OS commands as the www-data user in Expedition, which results in the disclosure of usernames, cleartext passwords, device configurations…

paloaltonetworks expedition
0.79EPSS
CVE-2020-2039
Media 5.3

An uncontrolled resource consumption vulnerability in Palo Alto Networks PAN-OS allows for a remote unauthenticated user to upload temporary files through the management web interface that are not properly deleted after the request is finished. It is possible …

paloaltonetworks pan-os
0.46EPSS
CVE-2016-4971
Alta 8.8

GNU wget before 1.18 allows remote servers to write to arbitrary files by redirecting a request from HTTP to a crafted FTP resource.

canonical ubuntu_linux · gnu wget · oracle solaris · paloaltonetworks pan-os
0.46EPSS
CVE-2016-8610
Alta 7.5

A denial of service flaw was found in OpenSSL 0.9.8, 1.0.1, 1.0.2 through 1.0.2h, and 1.1.0 in the way the TLS/SSL protocol defined processing of ALERT packets during a connection handshake. A remote attacker could use this flaw to make a TLS/SSL server consum…

debian debian_linux · fujitsu m10-1_firmware · fujitsu m10-4_firmware · fujitsu m10-4s_firmware · e altri 41
0.40EPSS
CVE-2016-9150
Critica 9.8

Buffer overflow in the management web interface in Palo Alto Networks PAN-OS before 5.0.20, 5.1.x before 5.1.13, 6.0.x before 6.0.15, 6.1.x before 6.1.15, 7.0.x before 7.0.11, and 7.1.x before 7.1.6 allows remote attackers to execute arbitrary code via unspeci…

paloaltonetworks pan-os
0.35EPSS
CVE-2021-3060
Alta 8.1

An OS command injection vulnerability in the Simple Certificate Enrollment Protocol (SCEP) feature of PAN-OS software allows an unauthenticated network-based attacker with specific knowledge of the firewall configuration to execute arbitrary code with root use…

paloaltonetworks pan-os · paloaltonetworks prisma_access
0.34EPSS