VYPR

Pan OS

by Paloaltonetworks

CVEs (258)

  • CVE-2020-1995MedMay 13, 2020
    risk 0.32cvss 4.9epss 0.01

    A NULL pointer dereference vulnerability in Palo Alto Networks PAN-OS allows an authenticated administrator to send a request that causes the rasmgr daemon to crash. Repeated attempts to send this request result in denial of service to all PAN-OS services by restarting the…

  • CVE-2026-0256MedMay 13, 2026
    risk 0.31cvss 4.8epss 0.00

    A stored cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS® software enables a malicious authenticated administrator to store a JavaScript payload using the web interface. This issue is applicable to PAN-OS software on PA-Series and VM-Series firewalls and…

  • CVE-2025-0137MedMay 14, 2025
    risk 0.31cvss epss 0.00

    An improper input neutralization vulnerability in the management web interface of the Palo Alto Networks PAN-OS® software enables a malicious authenticated read-write administrator to impersonate another legitimate authenticated PAN-OS administrator. The attacker must have…

  • CVE-2024-5920MedNov 14, 2024
    risk 0.31cvss 4.8epss 0.00

    A cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS software enables an authenticated read-write Panorama administrator to push a specially crafted configuration to a PAN-OS node. This enables impersonation of a legitimate PAN-OS administrator who can perform…

  • CVE-2024-9471MedOct 9, 2024
    risk 0.31cvss 4.7epss 0.00

    A privilege escalation (PE) vulnerability in the XML API of Palo Alto Networks PAN-OS software enables an authenticated PAN-OS administrator with restricted privileges to use a compromised XML API key to perform actions as a higher privileged PAN-OS administrator. For example,…

  • CVE-2020-1982MedJul 8, 2020
    risk 0.31cvss 4.8epss 0.00

    Certain communication between PAN-OS and cloud-delivered services inadvertently use TLS 1.0, which is known to be a cryptographically weak protocol. These cloud services include Cortex Data Lake, the Customer Support Portal, and the Prisma Access infrastructure. Conditions…

  • CVE-2026-0269MedJun 10, 2026
    risk 0.30cvss epss 0.00

    A memory corruption vulnerability in the processing of tunnel traffic in Palo Alto Networks PAN-OS® software allows an authenticated user to initiate system reboots using a maliciously crafted packet. Repeated attempts to initiate a reboot causes the firewall to enter…

  • CVE-2024-8688MedSep 11, 2024
    risk 0.29cvss 4.4epss 0.00

    An improper neutralization of matching symbols vulnerability in the Palo Alto Networks PAN-OS command line interface (CLI) enables authenticated administrators (including read-only administrators) with access to the CLI to to read arbitrary files on the firewall.

  • CVE-2024-5916MedAug 14, 2024
    risk 0.29cvss 4.4epss 0.00

    An information exposure vulnerability in Palo Alto Networks PAN-OS software enables a local system administrator to unintentionally disclose secrets, passwords, and tokens of external systems. A read-only administrator who has access to the config log, can read secrets,…

  • CVE-2023-0008MedMay 10, 2023
    risk 0.29cvss 4.4epss 0.01

    A file disclosure vulnerability in Palo Alto Networks PAN-OS software enables an authenticated read-write administrator with access to the web interface to export local files from the firewall through a race condition.

  • CVE-2021-3036MedApr 20, 2021
    risk 0.29cvss 4.4epss 0.00

    An information exposure through log file vulnerability exists in Palo Alto Networks PAN-OS software where secrets in PAN-OS XML API requests are logged in cleartext to the web server logs when the API is used incorrectly. This vulnerability applies only to PAN-OS appliances that…

  • CVE-2021-3032MedJan 13, 2021
    risk 0.29cvss 4.4epss 0.00

    An information exposure through log file vulnerability exists in Palo Alto Networks PAN-OS software where configuration secrets for the “http”, “email”, and “snmptrap” v3 log forwarding server profiles can be logged to the logrcvr.log system log. Logged information…

  • CVE-2024-5918MedNov 14, 2024
    risk 0.28cvss 4.3epss 0.00

    An improper certificate validation vulnerability in Palo Alto Networks PAN-OS software enables an authorized user with a specially crafted client certificate to connect to an impacted GlobalProtect portal or GlobalProtect gateway as a different legitimate user. This attack is…

  • CVE-2024-2433MedMar 13, 2024
    risk 0.28cvss 4.3epss 0.01

    An improper authorization vulnerability in Palo Alto Networks Panorama software enables an authenticated read-only administrator to upload files using the web interface and completely fill one of the disk partitions with those uploaded files, which prevents the ability to log…

  • CVE-2024-0011MedFeb 14, 2024
    risk 0.28cvss 4.3epss 0.00

    A reflected cross-site scripting (XSS) vulnerability in the Captive Portal feature of Palo Alto Networks PAN-OS software enables execution of malicious JavaScript (in the context of an authenticated Captive Portal user’s browser) if a user clicks on a malicious link, allowing…

  • CVE-2024-0010MedFeb 14, 2024
    risk 0.28cvss 4.3epss 0.01

    A reflected cross-site scripting (XSS) vulnerability in the GlobalProtect portal feature of Palo Alto Networks PAN-OS software enables execution of malicious JavaScript (in the context of a user’s browser) if a user clicks on a malicious link, allowing phishing attacks that…

  • CVE-2023-6789MedDec 13, 2023
    risk 0.28cvss 4.3epss 0.00

    A cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS software enables a malicious authenticated read-write administrator to store a JavaScript payload using the web interface. Then, when viewed by a properly authenticated administrator, the JavaScript payload…

  • CVE-2021-3031MedJan 13, 2021
    risk 0.28cvss 4.3epss 0.01

    Padding bytes in Ethernet packets on PA-200, PA-220, PA-500, PA-800, PA-2000 Series, PA-3000 Series, PA-3200 Series, PA-5200 Series, and PA-7000 Series firewalls are not cleared before the data frame is created. This leaks a small amount of random information from the firewall…

  • CVE-2018-10140MedAug 16, 2018
    risk 0.28cvss 4.3epss 0.02

    The PAN-OS Management Web Interface in Palo Alto Networks PAN-OS 8.1.2 and earlier may allow an authenticated user to shut down all management sessions, resulting in all logged in users to be redirected to the login page. PAN-OS 6.1, PAN-OS 7.1 and PAN-OS 8.0 are NOT affected.

  • CVE-2017-7217MedApr 14, 2017
    risk 0.28cvss 4.3epss 0.01

    The Management Web Interface in Palo Alto Networks PAN-OS before 7.0.14 and 7.1.x before 7.1.9 allows remote attackers to write to export files via unspecified parameters.