imPC@ndo EN

Vulnerabilità Palo Alto

371 CVE

CVE-2021-3047
Media 4.2

A cryptographically weak pseudo-random number generator (PRNG) is used during authentication to the Palo Alto Networks PAN-OS web interface. This enables an authenticated attacker, with the capability to observe their own authentication secrets over a long dur…

paloaltonetworks pan-os
0.00EPSS
CVE-2025-0118
Alta 8.0

A vulnerability in the Palo Alto Networks GlobalProtect app on Windows allows a remote attacker to run ActiveX controls within the context of an authenticated Windows user. This enables the attacker to run commands as if they are a legitimate authenticated use…

paloaltonetworks globalprotect
0.00EPSS
CVE-2024-3386
Media 5.3

An incorrect string comparison vulnerability in Palo Alto Networks PAN-OS software prevents Predefined Decryption Exclusions from functioning as intended. This can cause traffic destined for domains that are not specified in Predefined Decryption Exclusions to…

paloaltonetworks pan-os
0.00EPSS
CVE-2017-15870
Media 6.7

Palo Alto Networks GlobalProtect Agent before 4.0.3 allows attackers with administration rights on the local station to gain SYSTEM privileges via vectors involving "image path execution hijacking."

paloaltonetworks globalprotect
0.00EPSS
CVE-2020-1993
Bassa 3.7

The GlobalProtect Portal feature in PAN-OS does not set a new session identifier after a successful user login, which allows session fixation attacks, if an attacker is able to control a user's session ID. This issue affects: All PAN-OS 7.1 and 8.0 versions; P…

paloaltonetworks pan-os
0.00EPSS
CVE-2023-0007
Media 6.5

A cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS software on Panorama appliances enables an authenticated read-write administrator to store a JavaScript payload in the web interface that will execute in the context of another administrat…

paloaltonetworks pan-os
0.00EPSS
CVE-2018-9242
Media 5.5

The PAN-OS management web interface page in PAN-OS 6.1.20 and earlier, PAN-OS 7.1.16 and earlier, PAN-OS 8.0.9 and earlier may allow an attacker to delete files in the system via specific request parameters.

paloaltonetworks pan-os
0.00EPSS
CVE-2025-4232
Alta 8.8

An improper neutralization of wildcards vulnerability in the log collection feature of Palo Alto Networks GlobalProtect™ app on macOS allows a non administrative user to escalate their privileges to root.

paloaltonetworks globalprotect
0.00EPSS
CVE-2020-1982
Media 4.8

Certain communication between PAN-OS and cloud-delivered services inadvertently use TLS 1.0, which is known to be a cryptographically weak protocol. These cloud services include Cortex Data Lake, the Customer Support Portal, and the Prisma Access infrastructur…

paloaltonetworks pan-os
0.00EPSS
CVE-2023-6789
Media 4.3

A cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS software enables a malicious authenticated read-write administrator to store a JavaScript payload using the web interface. Then, when viewed by a properly authenticated administrator, the …

paloaltonetworks pan-os
0.00EPSS
CVE-2024-9468
Alta 7.5

A memory corruption vulnerability in Palo Alto Networks PAN-OS software allows an unauthenticated attacker to crash PAN-OS due to a crafted packet through the data plane, resulting in a denial of service (DoS) condition. Repeated attempts to trigger this condi…

paloaltonetworks pan-os
0.00EPSS
CVE-2024-5909
Media 5.5

A problem with a protection mechanism in the Palo Alto Networks Cortex XDR agent on Windows devices allows a low privileged local Windows user to disable the agent. This issue may be leveraged by malware to disable the Cortex XDR agent and then to perform mali…

paloaltonetworks cortex_xdr_agent
0.00EPSS
CVE-2024-8687
Alta 7.1

An information exposure vulnerability exists in Palo Alto Networks PAN-OS software that enables a GlobalProtect end user to learn both the configured GlobalProtect uninstall password and the configured disable or disconnect passcode. After the password or pass…

paloaltonetworks globalprotect · paloaltonetworks pan-os · paloaltonetworks prisma_access
0.00EPSS
CVE-2025-0114
Alta 7.5

A Denial of Service (DoS) vulnerability in the GlobalProtect feature of Palo Alto Networks PAN-OS software enables an unauthenticated attacker to render the service unavailable by sending a large number of specially crafted packets over a period of time. This …

paloaltonetworks pan-os
0.00EPSS
CVE-2024-0007
Media 6.8

A cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS software enables a malicious authenticated read-write administrator to store a JavaScript payload using the web interface on Panorama appliances. This enables the impersonation of another …

paloaltonetworks pan-os
0.00EPSS
CVE-2025-0130
Alta 7.5

A missing exception check in Palo Alto Networks PAN-OS® software with the web proxy feature enabled allows an unauthenticated attacker to send a burst of maliciously crafted packets that causes the firewall to become unresponsive and eventually reboot. Repeate…

paloaltonetworks pan-os
0.00EPSS
CVE-2026-0250
Alta 8.1

A buffer overflow vulnerability exists in the Palo Alto Networks GlobalProtect™ app that enables a man in the middle attacker to disrupt system processes and potentially execute arbitrary code with SYSTEM privileges. This vulnerability is triggered during the …

paloaltonetworks globalprotect
0.00EPSS
CVE-2024-2432
Media 4.5

A privilege escalation (PE) vulnerability in the Palo Alto Networks GlobalProtect app on Windows devices enables a local user to execute programs with elevated privileges. However, execution requires that the local user is able to successfully exploit a race c…

paloaltonetworks globalprotect
0.00EPSS
CVE-2024-0011
Media 4.3

A reflected cross-site scripting (XSS) vulnerability in the Captive Portal feature of Palo Alto Networks PAN-OS software enables execution of malicious JavaScript (in the context of an authenticated Captive Portal user’s browser) if a user clicks on a maliciou…

paloaltonetworks pan-os
0.00EPSS
CVE-2026-0265
Alta 8.1

An authentication bypass vulnerability in Palo Alto Networks PAN-OS® software enables an unauthenticated attacker with network access to bypass authentication controls when Cloud Authentication Service (CAS) is enabled. The risk is higher if CAS is enabled …

paloaltonetworks pan-os · siemens ruggedcom_ape1808_firmware
0.00EPSS
CVE-2018-9334
Media 5.5

The PAN-OS management web interface page in PAN-OS 6.1.20 and earlier, PAN-OS 7.1.16 and earlier, PAN-OS 8.0.8 and earlier, and PAN-OS 8.1.0 may allow an attacker to access the GlobalProtect password hashes of local users via manipulation of the HTML markup.

paloaltonetworks pan-os
0.00EPSS
CVE-2023-0010
Media 5.4

A reflected cross-site scripting (XSS) vulnerability in the Captive Portal feature of Palo Alto Networks PAN-OS software can allow a JavaScript payload to be executed in the context of an authenticated Captive Portal user’s browser when they click on a specifi…

paloaltonetworks pan-os
0.00EPSS
CVE-2026-0263
Critica 9.8

A buffer overflow vulnerability in the IKEv2 processing of Palo Alto Networks PAN-OS® software allows an unauthenticated network-based attacker to execute arbitrary code with elevated privileges on the firewall, or cause a denial of service (DoS) condition. …

paloaltonetworks pan-os
0.00EPSS
CVE-2020-1988
Media 4.2

An unquoted search path vulnerability in the Windows release of Global Protect Agent allows an authenticated local user with file creation privileges on the root of the OS disk (C:\) or to Program Files directory to gain system privileges. This issue affects P…

paloaltonetworks globalprotect
0.00EPSS
CVE-2024-5908
Alta 7.5

A problem with the Palo Alto Networks GlobalProtect app can result in exposure of encrypted user credentials, used for connecting to GlobalProtect, in application logs. Normally, these application logs are only viewable by local users and are included when gen…

paloaltonetworks globalprotect
0.00EPSS