imPC@ndo EN

Vulnerabilità Palo Alto

371 CVE

CVE-2024-5911
Media 4.9

An arbitrary file upload vulnerability in Palo Alto Networks Panorama software enables an authenticated read-write administrator with access to the web interface to disrupt system processes and crash the Panorama. Repeated attacks eventually cause the Panorama…

paloaltonetworks pan-os
0.01EPSS
CVE-2024-3383
Alta 7.4

A vulnerability in how Palo Alto Networks PAN-OS software processes data received from Cloud Identity Engine (CIE) agents enables modification of User-ID groups. This impacts user access to network resources where users may be inappropriately denied or allowed…

paloaltonetworks pan-os
0.01EPSS
CVE-2023-6794
Media 5.5

An arbitrary file upload vulnerability in Palo Alto Networks PAN-OS software enables an authenticated read-write administrator with access to the web interface to disrupt system processes and potentially execute arbitrary code with limited privileges on the fi…

paloaltonetworks pan-os
0.01EPSS
CVE-2024-2433
Media 4.3

An improper authorization vulnerability in Palo Alto Networks Panorama software enables an authenticated read-only administrator to upload files using the web interface and completely fill one of the disk partitions with those uploaded files, which prevents th…

paloaltonetworks pan-os
0.01EPSS
CVE-2020-2016
Alta 7.0

A race condition due to insecure creation of a file in a temporary directory vulnerability in PAN-OS allows for root privilege escalation from a limited linux user account. This allows an attacker who has escaped the restricted shell as a low privilege adminis…

paloaltonetworks pan-os
0.01EPSS
CVE-2023-6793
Bassa 2.7

An improper privilege management vulnerability in Palo Alto Networks PAN-OS software enables an authenticated read-only administrator to revoke active XML API keys from the firewall and disrupt XML API usage.

paloaltonetworks pan-os
0.01EPSS
CVE-2026-45172
Alta 8.8

Due to incomplete input validation in Idira Privileged Session Manager for SSH (PSMP) versions prior to 15.0.2, 14.6.3, 14.2.5, and 14.0.6, an authenticated, low-privileged user could potentially execute arbitrary commands on the PSMP host. CyberArk Security B…

paloaltonetworks idira_privileged_session_manager_for_ssh
0.01EPSS
CVE-2026-45171
Alta 8.8

Incomplete input validation and improperly configured folder permissions within Idira Privileged Session Manager (PSM) versions prior to 15.0.3, 14.6.3, 14.2.5, and 14.0.5, an authenticated, low-privileged user could potentially execute arbitrary code. CyberAr…

paloaltonetworks idira_privileged_session_manager
0.01EPSS
CVE-2017-7218
Alta 7.8

The Management Web Interface in Palo Alto Networks PAN-OS before 7.1.9 allows remote authenticated users to gain privileges via unspecified request parameters.

paloaltonetworks pan-os
0.01EPSS
CVE-2023-0008
Media 4.4

A file disclosure vulnerability in Palo Alto Networks PAN-OS software enables an authenticated read-write administrator with access to the web interface to export local files from the firewall through a race condition.

paloaltonetworks pan-os
0.01EPSS
CVE-2021-3031
Media 4.3

Padding bytes in Ethernet packets on PA-200, PA-220, PA-500, PA-800, PA-2000 Series, PA-3000 Series, PA-3200 Series, PA-5200 Series, and PA-7000 Series firewalls are not cleared before the data frame is created. This leaks a small amount of random information …

paloaltonetworks pan-os
0.01EPSS
CVE-2021-3039
Bassa 3.8

An information exposure through log file vulnerability exists in the Palo Alto Networks Prisma Cloud Compute Console where a secret used to authorize the role of the authenticated user is logged to a debug log file. Authenticated Operator role and Auditor role…

paloaltonetworks prisma_cloud
0.01EPSS
CVE-2022-0027
Media 4.3

An improper authorization vulnerability in Palo Alto Network Cortex XSOAR software enables authenticated users in non-Read-Only groups to generate an email report that contains summary information about all incidents in the Cortex XSOAR instance, including inc…

paloaltonetworks cortex_xsoar
0.01EPSS
CVE-2024-2550
Alta 7.5

A null pointer dereference vulnerability in the GlobalProtect gateway in Palo Alto Networks PAN-OS software enables an unauthenticated attacker to stop the GlobalProtect service on the firewall by sending a specially crafted packet that causes a denial of serv…

paloaltonetworks pan-os
0.01EPSS
CVE-2020-1977
Alta 7.5

Insufficient Cross-Site Request Forgery (XSRF) protection on Expedition Migration Tool allows remote unauthenticated attackers to hijack the authentication of administrators and to perform actions on the Expedition Migration Tool. This issue affects Expedition…

paloaltonetworks expedition_migration_tool
0.01EPSS
CVE-2024-0010
Media 4.3

A reflected cross-site scripting (XSS) vulnerability in the GlobalProtect portal feature of Palo Alto Networks PAN-OS software enables execution of malicious JavaScript (in the context of a user’s browser) if a user clicks on a malicious link, allowing phishin…

paloaltonetworks pan-os
0.01EPSS
CVE-2026-45177
Critica 9.1

Idira Secrets Manager SaaS Edge versions prior to 1.8 exhibit improper access control within its internal authentication components. A remote, unauthenticated attacker could exploit this by submitting a specially crafted request. Under specific circumstances, …

paloaltonetworks idira_secrets_manager_edge
0.01EPSS
CVE-2024-0008
Media 6.6

Web sessions in the management interface in Palo Alto Networks PAN-OS software do not expire in certain situations, making it susceptible to unauthorized access.

paloaltonetworks pan-os
0.01EPSS
CVE-2021-3049
Bassa 2.6

An improper authorization vulnerability in the Palo Alto Networks Cortex XSOAR server enables an authenticated network-based attacker with investigation read permissions to download files from incident investigations of which they are aware but are not a part …

paloaltonetworks cortex_xsoar
0.00EPSS
CVE-2025-0106
Media 5.3

A wildcard expansion vulnerability in Palo Alto Networks Expedition allows an unauthenticated attacker to enumerate files on the host filesystem.

paloaltonetworks expedition
0.00EPSS
CVE-2024-2551
Alta 7.5

A null pointer dereference vulnerability in Palo Alto Networks PAN-OS software enables an unauthenticated attacker to stop a core system service on the firewall by sending a crafted packet through the data plane that causes a denial of service (DoS) condition.…

paloaltonetworks pan-os
0.00EPSS
CVE-2024-5917
Media 4.9

A server-side request forgery in PAN-OS software enables an authenticated attacker with administrative privileges to use the administrative web interface as a proxy, which enables the attacker to view internal network resources not otherwise accessible.

paloaltonetworks pan-os
0.00EPSS
CVE-2026-0264
Critica 9.8

A buffer overflow vulnerability in the DNS proxy and DNS Server features of Palo Alto Networks PAN-OS® Software allows an unauthenticated attacker with network access to cause a denial of service (DoS) condition (all PAN-OS platforms except Cloud NGFW and Pris…

paloaltonetworks pan-os · siemens ruggedcom_ape1808_firmware
0.00EPSS
CVE-2024-2552
Media 6.0

A command injection vulnerability in Palo Alto Networks PAN-OS software enables an authenticated administrator to bypass system restrictions in the management plane and delete files on the firewall.

paloaltonetworks pan-os
0.00EPSS
CVE-2023-38046
Media 5.5

A vulnerability exists in Palo Alto Networks PAN-OS software that enables an authenticated administrator with the privilege to commit a specifically created configuration to read local files and resources from the system.

paloaltonetworks pan-os
0.00EPSS