← Back

Paloaltonetworks

paloaltonetworks

311 CVEs • 84 products

Products (84)

Click to collapse
Toggle
Pan Os
pan-os
Globalprotect
globalprotect
Expedition
expedition
Cortex Xsoar
cortex_xsoar
Prisma Access
prisma_access
Prisma Cloud
prisma_cloud
Traps
traps
Secdo
secdo
Netconnect
netconnect
Demisto
demisto
Minemeld
minemeld
Twistlock
twistlock
Vm Series
vm-series
Pa 7050
pa-7050
Pa 7080
pa-7080
Pa 200
pa-200
Pa 2020
pa-2020
Pa 2050
pa-2050
Pa 220
pa-220
Pa 3020
pa-3020
Pa 3050
pa-3050
Pa 3060
pa-3060
Pa 3220
pa-3220
Pa 3250
pa-3250
Pa 3260
pa-3260
Pa 500
pa-500
Pa 5200
pa-5200
Pa 800
pa-800
Pa 5410
pa-5410
Pa 5420
pa-5420
Pa 5430
pa-5430
Pa 5440
pa-5440
Pa 5445
pa-5445
Pa 1410
pa-1410
Pa 1420
pa-1420
Pa 3410
pa-3410
Pa 3420
pa-3420
Pa 3430
pa-3430
Pa 3440
pa-3440
Pa 410
pa-410
Pa 410r
pa-410r
Pa 410r 5g
pa-410r-5g
Pa 415
pa-415
Pa 415 5g
pa-415-5g
Pa 440
pa-440
Pa 445
pa-445
Pa 450
pa-450
Pa 450r
pa-450r
Pa 450r 5g
pa-450r-5g
Pa 455
pa-455
Pa 455 5g
pa-455-5g
Pa 455r 5g
pa-455r-5g
Pa 460
pa-460
Pa 501
pa-501
Pa 505
pa-505
Pa 510
pa-510
Pa 520
pa-520
Pa 540
pa-540
Pa 545 Poe
pa-545-poe
Pa 5450
pa-5450
Pa 550
pa-550
Pa 5540
pa-5540
Pa 555 Poe
pa-555-poe
Pa 5550
pa-5550
Pa 5560
pa-5560
Pa 5570
pa-5570
Pa 5580
pa-5580
Pa 560
pa-560
Pa 7500
pa-7500
Pa 7500 Dpc A
pa-7500-dpc-a
Vm 100
vm-100
Vm 300
vm-300
Vm 50
vm-50
Vm 500
vm-500
Vm 700
vm-700

CVEs (311)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Paloaltonetworks
1Pan Os
Nov 21, 2024
May 13, 2020
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
An OS Command Injection vulnerability in PAN-OS management server allows authenticated users to inject and execute arbitrary shell commands with root privileges. This issue affects: All versions of PAN-OS 7.1 and 8.0; PA...Show more
An OS Command Injection vulnerability in PAN-OS management server allows authenticated users to inject and execute arbitrary shell commands with root privileges. This issue affects: All versions of PAN-OS 7.1 and 8.0; PAN-OS 8.1 versions earlier than 8.1.14; PAN-OS 9.0 versions earlier than 9.0.7.Show less
1Paloaltonetworks
1Pan Os
Nov 21, 2024
May 13, 2020
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
A cleartext transmission of sensitive information vulnerability in Palo Alto Networks PAN-OS Panorama that discloses an authenticated PAN-OS administrator's PAN-OS session cookie. When an administrator issues a context s...Show more
A cleartext transmission of sensitive information vulnerability in Palo Alto Networks PAN-OS Panorama that discloses an authenticated PAN-OS administrator's PAN-OS session cookie. When an administrator issues a context switch request into a managed firewall with an affected PAN-OS Panorama version, their PAN-OS session cookie is transmitted over cleartext to the firewall. An attacker with the ability to intercept this network traffic between the firewall and Panorama can access the administrator's account and further manipulate devices managed by Panorama. This issue affects: PAN-OS 7.1 versions earlier than 7.1.26; PAN-OS 8.1 versions earlier than 8.1.13; PAN-OS 9.0 versions earlier than 9.0.6; PAN-OS 9.1 versions earlier than 9.1.1; All version of PAN-OS 8.0;Show less
1Paloaltonetworks
1Pan Os
Nov 21, 2024
May 13, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Improper restriction of XML external entity reference ('XXE') vulnerability in Palo Alto Networks Panorama management service allows remote unauthenticated attackers with network access to the Panorama management interfa...Show more
Improper restriction of XML external entity reference ('XXE') vulnerability in Palo Alto Networks Panorama management service allows remote unauthenticated attackers with network access to the Panorama management interface to read arbitrary files on the system. This issue affects: All versions of PAN-OS for Panorama 7.1 and 8.0; PAN-OS for Panorama 8.1 versions earlier than 8.1.13; PAN-OS for Panorama 9.0 versions earlier than 9.0.7.Show less
1Paloaltonetworks
1Pan Os
Nov 21, 2024
May 13, 2020
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
An improper input validation vulnerability in the configuration daemon of Palo Alto Networks PAN-OS Panorama allows for a remote unauthenticated user to send a specifically crafted registration request to the device that...Show more
An improper input validation vulnerability in the configuration daemon of Palo Alto Networks PAN-OS Panorama allows for a remote unauthenticated user to send a specifically crafted registration request to the device that causes the configuration service to crash. Repeated attempts to send this request result in denial of service to all PAN-OS Panorama services by restarting the device and putting it into maintenance mode. This issue affects: All versions of PAN-OS 7.1, PAN-OS 8.0; PAN-OS 8.1 versions earlier than 8.1.14; PAN-OS 9.0 versions earlier than 9.0.7; PAN-OS 9.1 versions earlier than 9.1.0.Show less
1Paloaltonetworks
1Pan Os
Nov 21, 2024
May 13, 2020
N/A· v4
7.2 HIGH· v3
9.0 HIGH· v2
An OS command injection vulnerability in PAN-OS management interface allows an authenticated administrator to execute arbitrary OS commands with root privileges. This issue affects: All versions of PAN-OS 7.1 and 8.0; PA...Show more
An OS command injection vulnerability in PAN-OS management interface allows an authenticated administrator to execute arbitrary OS commands with root privileges. This issue affects: All versions of PAN-OS 7.1 and 8.0; PAN-OS 8.1 versions earlier than 8.1.14; PAN-OS 9.0 versions earlier than 9.0.7.Show less
1Paloaltonetworks
1Pan Os
Nov 21, 2024
May 13, 2020
N/A· v4
7.2 HIGH· v3
9.0 HIGH· v2
An external control of filename vulnerability in the SD WAN component of Palo Alto Networks PAN-OS Panorama allows an authenticated administrator to send a request that results in the creation and write of an arbitrary f...Show more
An external control of filename vulnerability in the SD WAN component of Palo Alto Networks PAN-OS Panorama allows an authenticated administrator to send a request that results in the creation and write of an arbitrary file on all firewalls managed by the Panorama. In some cases this results in arbitrary code execution with root permissions. This issue affects: All versions of PAN-OS 7.1; PAN-OS 8.1 versions earlier than 8.1.14; PAN-OS 9.0 versions earlier than 9.0.7.Show less
1Paloaltonetworks
1Pan Os
Nov 21, 2024
May 13, 2020
N/A· v4
7.2 HIGH· v3
9.0 HIGH· v2
An OS command injection and external control of filename vulnerability in Palo Alto Networks PAN-OS allows authenticated administrators to execute code with root privileges or delete arbitrary system files and impact the...Show more
An OS command injection and external control of filename vulnerability in Palo Alto Networks PAN-OS allows authenticated administrators to execute code with root privileges or delete arbitrary system files and impact the system's integrity or cause a denial of service condition. This issue affects: All versions of PAN-OS 7.1 and 8.0; PAN-OS 8.1 versions earlier than 8.1.14.Show less
1Paloaltonetworks
1Pan Os
Nov 21, 2024
May 13, 2020
N/A· v4
7.2 HIGH· v3
9.0 HIGH· v2
An OS command injection vulnerability in the management server component of PAN-OS allows an authenticated user to potentially execute arbitrary commands with root privileges. This issue affects: All PAN-OS 7.1 versions;...Show more
An OS command injection vulnerability in the management server component of PAN-OS allows an authenticated user to potentially execute arbitrary commands with root privileges. This issue affects: All PAN-OS 7.1 versions; PAN-OS 8.1 versions earlier than 8.1.14; PAN-OS 9.0 versions earlier than 9.0.7.Show less
1Paloaltonetworks
1Pan Os
Nov 21, 2024
May 13, 2020
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
A stack-based buffer overflow vulnerability in the management server component of PAN-OS that allows an authenticated user to potentially execute arbitrary code with root privileges. This issue affects: All versions of P...Show more
A stack-based buffer overflow vulnerability in the management server component of PAN-OS that allows an authenticated user to potentially execute arbitrary code with root privileges. This issue affects: All versions of PAN-OS 7.1 and 8.0; PAN-OS 8.1 versions earlier than 8.1.14.Show less
1Paloaltonetworks
1Pan Os
Nov 21, 2024
May 13, 2020
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A cross-site scripting (XSS) vulnerability exists when visiting malicious websites with the Palo Alto Networks GlobalProtect Clientless VPN that can compromise the user's active session. This issue affects: PAN-OS 7.1 ve...Show more
A cross-site scripting (XSS) vulnerability exists when visiting malicious websites with the Palo Alto Networks GlobalProtect Clientless VPN that can compromise the user's active session. This issue affects: PAN-OS 7.1 versions earlier than 7.1.26; PAN-OS 8.1 versions earlier than 8.1.13; PAN-OS 9.0 versions earlier than 9.0.7; All versions of PAN-OS 8.0.Show less
1Paloaltonetworks
1Globalprotect
Nov 21, 2024
May 13, 2020
N/A· v4
5.5 MEDIUM· v3
1.7 LOW· v2
Under certain circumstances a user's password may be logged in cleartext in the PanGPS.log diagnostic file when logs are collected for troubleshooting on GlobalProtect app (also known as GlobalProtect Agent) for MacOS an...Show more
Under certain circumstances a user's password may be logged in cleartext in the PanGPS.log diagnostic file when logs are collected for troubleshooting on GlobalProtect app (also known as GlobalProtect Agent) for MacOS and Windows. For this issue to occur all of these conditions must be true: (1) 'Save User Credential' option should be set to 'Yes' in the GlobalProtect Portal's Agent configuration, (2) the GlobalProtect user manually selects a gateway, (3) and the logging level is set to 'Dump' while collecting troubleshooting logs. This issue does not affect GlobalProtect app on other platforms (for example iOS/Android/Linux). This issue affects GlobalProtect app 5.0 versions earlier than 5.0.9, GlobalProtect app 5.1 versions earlier than 5.1.2 on Windows or MacOS. Since becoming aware of the issue, Palo Alto Networks has safely deleted all the known GlobalProtectLogs zip files sent by customers with the credentials. We now filter and remove these credentials from all files sent to Customer Support. The GlobalProtectLogs zip files uploaded to Palo Alto Networks systems were only accessible by authorized personnel with valid Palo Alto Networks credentials. We do not have any evidence of malicious access or use of these credentials.Show less
1Paloaltonetworks
1Pan Os
Nov 21, 2024
May 13, 2020
N/A· v4
6.5 MEDIUM· v3
8.5 HIGH· v2
An external control of filename vulnerability in the command processing of PAN-OS allows an authenticated administrator to delete arbitrary system files affecting the integrity of the system or causing denial of service...Show more
An external control of filename vulnerability in the command processing of PAN-OS allows an authenticated administrator to delete arbitrary system files affecting the integrity of the system or causing denial of service to all PAN-OS services. This issue affects: All versions of PAN-OS 7.1 and 8.0; PAN-OS 8.1 versions before 8.1.14; PAN-OS 9.0 versions before 9.0.7; PAN-OS 9.1 versions before 9.1.1.Show less
1Paloaltonetworks
1Pan Os
Nov 21, 2024
May 13, 2020
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
An authentication bypass by spoofing vulnerability exists in the authentication daemon and User-ID components of Palo Alto Networks PAN-OS by failing to verify the integrity of the Kerberos key distribution center (KDC)...Show more
An authentication bypass by spoofing vulnerability exists in the authentication daemon and User-ID components of Palo Alto Networks PAN-OS by failing to verify the integrity of the Kerberos key distribution center (KDC) before authenticating users. This affects all forms of authentication that use a Kerberos authentication profile. A man-in-the-middle type of attacker with the ability to intercept communication between PAN-OS and KDC can login to PAN-OS as an administrator. This issue affects: PAN-OS 7.1 versions earlier than 7.1.26; PAN-OS 8.1 versions earlier than 8.1.13; PAN-OS 9.0 versions earlier than 9.0.6; All version of PAN-OS 8.0.Show less
1Paloaltonetworks
1Pan Os
Nov 21, 2024
May 13, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An external control of path and data vulnerability in the Palo Alto Networks PAN-OS Panorama XSLT processing logic that allows an unauthenticated user with network access to PAN-OS management interface to write attacker...Show more
An external control of path and data vulnerability in the Palo Alto Networks PAN-OS Panorama XSLT processing logic that allows an unauthenticated user with network access to PAN-OS management interface to write attacker supplied file on the system and elevate privileges. This issue affects: All PAN-OS 7.1 Panorama and 8.0 Panorama versions; PAN-OS 8.1 versions earlier than 8.1.12 on Panorama; PAN-OS 9.0 versions earlier than 9.0.6 on Panorama.Show less
1Paloaltonetworks
1Pan Os
Nov 21, 2024
May 13, 2020
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
An improper authorization vulnerability in PAN-OS that mistakenly uses the permissions of local linux users instead of the intended SAML permissions of the account when the username is shared for the purposes of SSO auth...Show more
An improper authorization vulnerability in PAN-OS that mistakenly uses the permissions of local linux users instead of the intended SAML permissions of the account when the username is shared for the purposes of SSO authentication. This can result in authentication bypass and unintended resource access for the user. This issue affects: PAN-OS 7.1 versions earlier than 7.1.26; PAN-OS 8.1 versions earlier than 8.1.13; PAN-OS 9.0 versions earlier than 9.0.6; PAN-OS 9.1 versions earlier than 9.1.1; All versions of PAN-OS 8.0.Show less
1Paloaltonetworks
1Pan Os
Nov 21, 2024
May 13, 2020
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
An open redirection vulnerability in the GlobalProtect component of Palo Alto Networks PAN-OS allows an attacker to specify an arbitrary redirection target away from the trusted GlobalProtect gateway. If the user then su...Show more
An open redirection vulnerability in the GlobalProtect component of Palo Alto Networks PAN-OS allows an attacker to specify an arbitrary redirection target away from the trusted GlobalProtect gateway. If the user then successfully authenticates it will cause them to access an unexpected and potentially malicious website. This issue affects: PAN-OS 7.1 versions earlier than 7.1.26; PAN-OS 8.0 versions earlier than 8.0.14.Show less
1Paloaltonetworks
1Pan Os
Nov 21, 2024
May 13, 2020
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
A missing authorization vulnerability in the management server component of PAN-OS Panorama allows a remote unauthenticated user to inject messages into the management server ms.log file. This vulnerability can be levera...Show more
A missing authorization vulnerability in the management server component of PAN-OS Panorama allows a remote unauthenticated user to inject messages into the management server ms.log file. This vulnerability can be leveraged to obfuscate an ongoing attack or fabricate log entries in the ms.log file This issue affects: All versions of PAN-OS 7.1 and 8.0; PAN-OS 8.1 versions earlier than 8.1.14; PAN-OS 9.0 versions earlier than 9.0.9.Show less
1Paloaltonetworks
1Pan Os
Nov 21, 2024
May 13, 2020
N/A· v4
4.9 MEDIUM· v3
6.8 MEDIUM· v2
A NULL pointer dereference vulnerability in Palo Alto Networks PAN-OS allows an authenticated administrator to send a request that causes the rasmgr daemon to crash. Repeated attempts to send this request result in denia...Show more
A NULL pointer dereference vulnerability in Palo Alto Networks PAN-OS allows an authenticated administrator to send a request that causes the rasmgr daemon to crash. Repeated attempts to send this request result in denial of service to all PAN-OS services by restarting the device and putting it into maintenance mode. This issue affects: PAN-OS 9.1 versions earlier than 9.1.2.Show less
1Paloaltonetworks
1Pan Os
Nov 21, 2024
May 13, 2020
N/A· v4
4.4 MEDIUM· v3
4.9 MEDIUM· v2
A predictable temporary file vulnerability in PAN-OS allows a local authenticated user with shell access to corrupt arbitrary system files affecting the integrity of the system. This issue affects: All versions of PAN-OS...Show more
A predictable temporary file vulnerability in PAN-OS allows a local authenticated user with shell access to corrupt arbitrary system files affecting the integrity of the system. This issue affects: All versions of PAN-OS 7.1 and 8.0; PAN-OS 8.1 versions earlier than 8.1.13; PAN-OS 9.0 versions earlier than 9.0.7.Show less
1Paloaltonetworks
1Pan Os
Nov 21, 2024
May 13, 2020
N/A· v4
5.4 MEDIUM· v3
5.5 MEDIUM· v2
The GlobalProtect Portal feature in PAN-OS does not set a new session identifier after a successful user login, which allows session fixation attacks, if an attacker is able to control a user's session ID. This issue aff...Show more
The GlobalProtect Portal feature in PAN-OS does not set a new session identifier after a successful user login, which allows session fixation attacks, if an attacker is able to control a user's session ID. This issue affects: All PAN-OS 7.1 and 8.0 versions; PAN-OS 8.1 versions earlier than 8.1.14; PAN-OS 9.0 versions earlier than 9.0.8.Show less