imPC@ndo IT

Palo Alto vulnerabilities

371 CVE

CVE-2021-3053
High 7.5

An improper handling of exceptional conditions vulnerability exists in the Palo Alto Networks PAN-OS dataplane that enables an unauthenticated network-based attacker to send specifically crafted traffic through the firewall that causes the service to crash. Re…

paloaltonetworks pan-os
0.01EPSS
CVE-2020-1979
High 8.1

A format string vulnerability in the PAN-OS log daemon (logd) on Panorama allows a network based attacker with knowledge of registered firewall devices and access to Panorama management interfaces to execute arbitrary code, bypassing the restricted shell and e…

paloaltonetworks pan-os
0.01EPSS
CVE-2020-1975
Medium 6.8

Missing XML validation vulnerability in the PAN-OS web interface on Palo Alto Networks PAN-OS software allows authenticated users to inject arbitrary XML that results in privilege escalation. This issue affects PAN-OS 8.1 versions earlier than PAN-OS 8.1.12 an…

paloaltonetworks pan-os
0.01EPSS
CVE-2017-6356
Medium 5.3

Palo Alto Networks Terminal Services (aka TS) Agent 6.0, 7.0, and 8.0 before 8.0.1 uses weak permissions for unspecified resources, which allows attackers to obtain sensitive session information via unknown vectors.

paloaltonetworks terminal_services_agent
0.01EPSS
CVE-2017-5329
High 7.8

Palo Alto Networks Terminal Services Agent before 7.0.7 allows local users to gain privileges via vectors that trigger an out-of-bounds write operation.

paloaltonetworks terminal_services_agent
0.01EPSS
CVE-2017-7409
Medium 6.1

Palo Alto Networks PAN-OS before 7.0.15 has XSS in the GlobalProtect external interface via crafted request parameters, aka PAN-SA-2017-0011 and PAN-70674.

paloaltonetworks pan-os
0.01EPSS
CVE-2026-0288
High 7.5

Multiple buffer overflow vulnerabilities in the User-ID Terminal Server Agent (TSA) component of Palo Alto Networks PAN-OS software allow an unauthenticated attacker with network access to cause a denial of service (DoS) condition or potentially execute arbitr…

paloaltonetworks pan-os
0.01EPSS
CVE-2020-2003
Medium 6.5

An external control of filename vulnerability in the command processing of PAN-OS allows an authenticated administrator to delete arbitrary system files affecting the integrity of the system or causing denial of service to all PAN-OS services. This issue affec…

paloaltonetworks pan-os
0.01EPSS
CVE-2024-3382
High 7.5

A memory leak exists in Palo Alto Networks PAN-OS software that enables an attacker to send a burst of crafted packets through the firewall that eventually prevents the firewall from processing traffic. This issue applies only to PA-5400 Series devices that ar…

paloaltonetworks pan-os
0.01EPSS
CVE-2021-3054
High 7.2

A time-of-check to time-of-use (TOCTOU) race condition vulnerability in the Palo Alto Networks PAN-OS web interface enables an authenticated administrator with permission to upload plugins to execute arbitrary code with root user privileges. This issue impacts…

paloaltonetworks pan-os
0.01EPSS
CVE-2024-3385
High 7.5

A packet processing mechanism in Palo Alto Networks PAN-OS software enables a remote attacker to reboot hardware-based firewalls. Repeated attacks eventually cause the firewall to enter maintenance mode, which requires manual intervention to bring the firewall…

paloaltonetworks pan-os
0.01EPSS
CVE-2017-5328
High 7.5

Palo Alto Networks Terminal Services Agent before 7.0.7 allows attackers to spoof arbitrary users via unspecified vectors.

paloaltonetworks terminal_services_agent
0.01EPSS
CVE-2020-1996
Medium 5.3

A missing authorization vulnerability in the management server component of PAN-OS Panorama allows a remote unauthenticated user to inject messages into the management server ms.log file. This vulnerability can be leveraged to obfuscate an ongoing attack or fa…

paloaltonetworks pan-os
0.01EPSS
CVE-2021-3063
High 7.5

An improper handling of exceptional conditions vulnerability exists in Palo Alto Networks GlobalProtect portal and gateway interfaces that enables an unauthenticated network-based attacker to send specifically crafted traffic to a GlobalProtect interface that …

paloaltonetworks pan-os
0.01EPSS
CVE-2019-1577
Medium 6.3

Code injection vulnerability in Palo Alto Networks Traps 5.0.5 and earlier may allow an authenticated attacker to inject arbitrary JavaScript or HTML.

paloaltonetworks traps
0.01EPSS
CVE-2020-1997
Medium 5.3

An open redirection vulnerability in the GlobalProtect component of Palo Alto Networks PAN-OS allows an attacker to specify an arbitrary redirection target away from the trusted GlobalProtect gateway. If the user then successfully authenticates it will cause t…

paloaltonetworks pan-os
0.01EPSS
CVE-2020-1998
Medium 5.4

An improper authorization vulnerability in PAN-OS that mistakenly uses the permissions of local linux users instead of the intended SAML permissions of the account when the username is shared for the purposes of SSO authentication. This can result in authentic…

paloaltonetworks pan-os
0.01EPSS
CVE-2024-3384
High 7.5

A vulnerability in Palo Alto Networks PAN-OS software enables a remote attacker to reboot PAN-OS firewalls when receiving Windows New Technology LAN Manager (NTLM) packets from Windows servers. Repeated attacks eventually cause the firewall to enter maintenanc…

paloaltonetworks pan-os
0.01EPSS
CVE-2022-0030
High 8.1

An authentication bypass vulnerability in the Palo Alto Networks PAN-OS 8.1 web interface allows a network-based attacker with specific knowledge of the target firewall or Panorama appliance to impersonate an existing PAN-OS administrator and perform privilege…

paloaltonetworks pan-os
0.01EPSS
CVE-2019-1568
Medium 6.1

Cross-site scripting (XSS) vulnerability in Palo Alto Networks Demisto 4.5 build 40249 may allow an unauthenticated attacker to run arbitrary JavaScript or HTML.

paloaltonetworks demisto
0.01EPSS
CVE-2021-3061
Medium 6.4

An OS command injection vulnerability in the Palo Alto Networks PAN-OS command line interface (CLI) enables an authenticated administrator with access to the CLI to execute arbitrary OS commands to escalate privileges. This issue impacts: PAN-OS 8.1 versions e…

paloaltonetworks pan-os · paloaltonetworks prisma_access
0.01EPSS
CVE-2021-3048
Medium 5.9

Certain invalid URL entries contained in an External Dynamic List (EDL) cause the Device Server daemon (devsrvr) to stop responding. This condition causes subsequent commits on the firewall to fail and prevents administrators from performing commits and config…

paloaltonetworks pan-os
0.01EPSS
CVE-2017-5584
Medium 5.4

Cross-site scripting (XSS) vulnerability in the Management Web Interface in Palo Alto Networks PAN-OS 5.1, 6.x before 6.1.16, 7.0.x before 7.0.13, and 7.1.x before 7.1.8 allows remote authenticated users to inject arbitrary web script or HTML via unspecified v…

paloaltonetworks pan-os
0.01EPSS
CVE-2020-2005
High 7.1

A cross-site scripting (XSS) vulnerability exists when visiting malicious websites with the Palo Alto Networks GlobalProtect Clientless VPN that can compromise the user's active session. This issue affects: PAN-OS 7.1 versions earlier than 7.1.26; PAN-OS 8.1 v…

paloaltonetworks pan-os
0.01EPSS
CVE-2020-2017
High 8.8

A DOM-Based Cross Site Scripting Vulnerability exists in PAN-OS and Panorama Management Web Interfaces. A remote attacker able to convince an authenticated administrator to click on a crafted link to PAN-OS and Panorama Web Interfaces could execute arbitrary J…

paloaltonetworks pan-os
0.01EPSS