imPC@ndo EN

Vulnerabilità Palo Alto

371 CVE

CVE-2020-1981
Alta 7.0

A predictable temporary filename vulnerability in PAN-OS allows local privilege escalation. This issue allows a local attacker who bypassed the restricted shell to execute commands as a low privileged user and gain root access on the PAN-OS hardware or virtual…

paloaltonetworks pan-os
0.00EPSS
CVE-2026-45178
Alta 8.1

Idira Secrets Manager Self-Hosted versions 13.8.0 and lower exhibit improper access control within internal cluster endpoints. A remote, authenticated attacker possessing standard node-level credentials could leverage these endpoints to potentially retrieve un…

paloaltonetworks idira_secrets_manager · paloaltonetworks idira_secrets_manager_credential_providers
0.00EPSS
CVE-2026-0262
Alta 7.5

Multiple denial of service vulnerabilities in Palo Alto Networks PAN-OS® software allow an unauthenticated attacker with network access to cause a denial of service (DoS) condition by sending specially crafted network traffic. Panorama and Cloud NGFW are not…

paloaltonetworks pan-os · siemens ruggedcom_ape1808_firmware
0.00EPSS
CVE-2025-0104
Media 6.1

A reflected cross-site scripting (XSS) vulnerability in Palo Alto Networks Expedition enables attackers to execute malicious JavaScript code in the context of an authenticated Expedition user’s browser if that authenticated user clicks a malicious link that al…

paloaltonetworks expedition
0.00EPSS
CVE-2016-1712
Alta 7.8

Palo Alto Networks PAN-OS before 5.0.19, 5.1.x before 5.1.12, 6.0.x before 6.0.14, 6.1.x before 6.1.12, and 7.0.x before 7.0.8 might allow local users to gain privileges by leveraging improper sanitization of the root_reboot local invocation.

paloaltonetworks pan-os
0.00EPSS
CVE-2026-45169
Alta 8.6

Idira Privileged Access Manager (PAM) Self-Hosted Vault versions prior to 15.0.3, 14.6.5, 14.2.7, and 14.0.8 exhibit a validation vulnerability. Under specific circumstances and configuration scenarios, processing unexpected input could potentially lead to an …

paloaltonetworks idira_privileged_access_manager_vault
0.00EPSS
CVE-2024-3388
Media 4.1

A vulnerability in the GlobalProtect Gateway in Palo Alto Networks PAN-OS software enables an authenticated attacker to impersonate another user and send network packets to internal assets. However, this vulnerability does not allow the attacker to receive res…

paloaltonetworks pan-os · paloaltonetworks prisma_access
0.00EPSS
CVE-2024-5919
Media 6.5

A blind XML External Entities (XXE) injection vulnerability in the Palo Alto Networks PAN-OS software enables an authenticated attacker to exfiltrate arbitrary files from firewalls to an attacker controlled server. This attack requires network access to the fi…

paloaltonetworks pan-os
0.00EPSS
CVE-2020-2048
Bassa 3.3

An information exposure through log file vulnerability exists where the password for the configured system proxy server for a PAN-OS appliance may be displayed in cleartext when using the CLI in Palo Alto Networks PAN-OS software. This issue impacts: PAN-OS 8.…

paloaltonetworks pan-os
0.00EPSS
CVE-2020-2049
Alta 7.8

A local privilege escalation vulnerability exists in Palo Alto Networks Cortex XDR Agent on the Windows platform that allows an authenticated local Windows user to execute programs with SYSTEM privileges. This requires the user to have the privilege to create …

paloaltonetworks cortex_xdr_agent
0.00EPSS
CVE-2026-0259
Alta 8.8

An arbitrary File Read and Delete Vulnerability in Palo Alto Networks WildFire® WF-500 and WF-500-B appliances enables users to read sensitive information and delete arbitrary files. This vulnerability affects WF-500 and WF-500-B appliances running in the defa…

paloaltonetworks pan-os
0.00EPSS
CVE-2026-0241
Alta 7.2

Incorrect Authorization vulnerabilities in Trust Protection Foundation allow attackers to bypass access controls and perform unauthorized actions on restricted resources.

paloaltonetworks trust_protection_foundation
0.00EPSS
CVE-2026-0279
Media 6.1

Multiple cross site scripting vulnerabilities in the User-ID™ Authentication Portal (aka Captive Portal) service, GlobalProtect™ gateway/portal features and Clientless VPN of Palo Alto Networks PAN-OS® software enables a malicious unauthenticated user to store…

paloaltonetworks pan-os
0.00EPSS
CVE-2019-17437
Alta 7.8

An improper authentication check in Palo Alto Networks PAN-OS may allow an authenticated low privileged non-superuser custom role user to elevate privileges and become superuser. This issue affects PAN-OS 7.1 versions prior to 7.1.25; 8.0 versions prior to 8.0…

paloaltonetworks pan-os
0.00EPSS
CVE-2025-0124
Bassa 3.8

An authenticated file deletion vulnerability in the Palo Alto Networks PAN-OS® software enables an authenticated attacker with network access to the management web interface to delete certain files as the “nobody” user; this includes limited logs and configura…

paloaltonetworks pan-os
0.00EPSS
CVE-2026-0258
Critica 9.1

A server-side request forgery (SSRF) vulnerability in the IKEv2 implementation of Palo Alto Networks PAN-OS® software allows an unauthenticated attacker to cause the firewall to send network requests to unintended destinations or cause a denial of service (DoS…

paloaltonetworks pan-os · siemens ruggedcom_ape1808_firmware
0.00EPSS
CVE-2026-0287
Alta 7.5

Multiple denial of service vulnerabilities in Palo Alto Networks PAN-OS® software allow an unauthenticated attacker with network access to cause a denial of service (DoS) condition by sending specially crafted network traffic to or through a dataplane interfac…

paloaltonetworks cloud_ngfw · paloaltonetworks pan-os
0.00EPSS
CVE-2024-8691
Alta 7.1

A vulnerability in the GlobalProtect portal in Palo Alto Networks PAN-OS software enables a malicious authenticated GlobalProtect user to impersonate another GlobalProtect user. Active GlobalProtect users impersonated by an attacker who is exploiting this vuln…

paloaltonetworks pan-os
0.00EPSS
CVE-2020-2004
Media 6.8

Under certain circumstances a user's password may be logged in cleartext in the PanGPS.log diagnostic file when logs are collected for troubleshooting on GlobalProtect app (also known as GlobalProtect Agent) for MacOS and Windows. For this issue to occur all o…

paloaltonetworks globalprotect
0.00EPSS
CVE-2020-1984
Alta 7.8

Secdo tries to execute a script at a hardcoded path if present, which allows a local authenticated user with 'create folders or append data' access to the root of the OS disk (C:\) to gain system privileges if the path does not already exist or is writable. Th…

paloaltonetworks secdo
0.00EPSS
CVE-2019-17436
Alta 7.1

A Local Privilege Escalation vulnerability exists in GlobalProtect Agent for Linux and Mac OS X version 5.0.4 and earlier and version 4.1.12 and earlier, that can allow non-root users to overwrite root files on the file system.

paloaltonetworks globalprotect
0.00EPSS
CVE-2020-1978
Media 5.8

TechSupport files generated on Palo Alto Networks VM Series firewalls for Microsoft Azure platform configured with high availability (HA) inadvertently collect Azure dashboard service account credentials. These credentials are equivalent to the credentials ass…

paloaltonetworks pan-os · paloaltonetworks vm-series
0.00EPSS
CVE-2023-3280
Media 5.5

A problem with a protection mechanism in the Palo Alto Networks Cortex XDR agent on Windows devices allows a local user to disable the agent.

paloaltonetworks cortex_xdr_agent
0.00EPSS
CVE-2020-2020
Media 5.5

An improper handling of exceptional conditions vulnerability in Cortex XDR Agent allows a local authenticated Windows user to create files in the software's internal program directory that prevents the Cortex XDR Agent from starting. The exceptional condition …

paloaltonetworks cortex_xdr_agent
0.00EPSS
CVE-2020-1987
Bassa 3.9

An information exposure vulnerability in the logging component of Palo Alto Networks Global Protect Agent allows a local authenticated user to read VPN cookie information when the troubleshooting logging level is set to "Dump". This issue affects Palo Alto Net…

paloaltonetworks globalprotect
0.00EPSS