VYPR

Pan OS

by Paloaltonetworks

CVEs (258)

  • CVE-2024-3388MedApr 10, 2024
    risk 0.27cvss 4.1epss 0.00

    A vulnerability in the GlobalProtect Gateway in Palo Alto Networks PAN-OS software enables an authenticated attacker to impersonate another user and send network packets to internal assets. However, this vulnerability does not allow the attacker to receive response packets from…

  • CVE-2023-0005MedApr 12, 2023
    risk 0.27cvss 4.1epss 0.00

    A vulnerability in Palo Alto Networks PAN-OS software enables an authenticated administrator to expose the plaintext values of secrets stored in the device configuration and encrypted API keys.

  • CVE-2022-0022MedMar 9, 2022
    risk 0.27cvss 4.1epss 0.00

    Usage of a weak cryptographic algorithm in Palo Alto Networks PAN-OS software where the password hashes of administrator and local user accounts are not created with a sufficient level of computational effort, which allows for password cracking attacks on accounts in normal…

  • CVE-2021-3047MedAug 11, 2021
    risk 0.27cvss 4.2epss 0.00

    A cryptographically weak pseudo-random number generator (PRNG) is used during authentication to the Palo Alto Networks PAN-OS web interface. This enables an authenticated attacker, with the capability to observe their own authentication secrets over a long duration on the PAN-OS…

  • CVE-2020-1994MedMay 13, 2020
    risk 0.27cvss 4.1epss 0.00

    A predictable temporary file vulnerability in PAN-OS allows a local authenticated user with shell access to corrupt arbitrary system files affecting the integrity of the system. This issue affects: All versions of PAN-OS 7.1 and 8.0; PAN-OS 8.1 versions earlier than 8.1.13;…

  • CVE-2025-0124LowApr 11, 2025
    risk 0.25cvss 3.8epss 0.00

    An authenticated file deletion vulnerability in the Palo Alto Networks PAN-OS® software enables an authenticated attacker with network access to the management web interface to delete certain files as the “nobody” user; this includes limited logs and configuration files but…

  • CVE-2020-1993LowMay 13, 2020
    risk 0.24cvss 3.7epss 0.00

    The GlobalProtect Portal feature in PAN-OS does not set a new session identifier after a successful user login, which allows session fixation attacks, if an attacker is able to control a user's session ID. This issue affects: All PAN-OS 7.1 and 8.0 versions; PAN-OS 8.1 versions…

  • CVE-2020-2044LowSep 9, 2020
    risk 0.22cvss 3.3epss 0.01

    An information exposure through log file vulnerability where an administrator's password or other sensitive information may be logged in cleartext while using the CLI in Palo Alto Networks PAN-OS software. The opcmdhistory.log file was introduced to track operational command…

  • CVE-2020-2043LowSep 9, 2020
    risk 0.22cvss 3.3epss 0.01

    An information exposure through log file vulnerability where sensitive fields are recorded in the configuration log without masking on Palo Alto Networks PAN-OS software when the after-change-detail custom syslog field is enabled for configuration logs and the sensitive field…

  • CVE-2025-0133LowMay 14, 2025
    risk 0.21cvss epss 0.46

    A reflected cross-site scripting (XSS) vulnerability in the GlobalProtect™ gateway and portal features of Palo Alto Networks PAN-OS® software enables execution of malicious JavaScript in the context of an authenticated Captive Portal user's browser when they click on a…

  • CVE-2020-2048LowNov 12, 2020
    risk 0.21cvss 3.3epss 0.00

    An information exposure through log file vulnerability exists where the password for the configured system proxy server for a PAN-OS appliance may be displayed in cleartext when using the CLI in Palo Alto Networks PAN-OS software. This issue impacts: PAN-OS 8.1 versions earlier…

  • CVE-2020-2035LowAug 12, 2020
    risk 0.20cvss 3.0epss 0.01

    When SSL/TLS Forward Proxy Decryption mode has been configured to decrypt the web transactions, the PAN-OS URL filtering feature inspects the HTTP Host and URL path headers for policy enforcement on the decrypted HTTPS web transactions but does not consider Server Name…

  • CVE-2025-4614LowOct 9, 2025
    risk 0.18cvss 2.7epss 0.00

    An information disclosure vulnerability in Palo Alto Networks PAN-OS® software enables an authenticated administrator to view session tokens of users authenticated to the firewall web UI. This may allow impersonation of users whose session tokens are leaked.   The security…

  • CVE-2023-6793LowDec 13, 2023
    risk 0.18cvss 2.7epss 0.01

    An improper privilege management vulnerability in Palo Alto Networks PAN-OS software enables an authenticated read-only administrator to revoke active XML API keys from the firewall and disrupt XML API usage.

  • CVE-2021-3037LowApr 20, 2021
    risk 0.15cvss 2.3epss 0.00

    An information exposure through log file vulnerability exists in Palo Alto Networks PAN-OS software where the connection details for a scheduled configuration export are logged in system logs. Logged information includes the cleartext username, password, and IP address used to…

  • CVE-2026-0301LowAug 13, 2026
    risk 0.11cvss epss 0.00

    An information disclosure vulnerability in the URL Filtering feature of Palo Alto Networks PAN-OS® software enables an unauthenticated user with network access to obtain sensitive information. Panorama is not impacted by this vulnerability.

  • CVE-2026-0228LowFeb 11, 2026
    risk 0.08cvss epss 0.00

    An improper certificate validation vulnerability in PAN-OS allows users to connect Terminal Server Agents on Windows to PAN-OS using expired certificates even if the PAN-OS configuration would not normally permit them to do so.

  • CVE-2026-0266LowJun 10, 2026
    risk 0.07cvss epss 0.00

    A cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS® software enables a malicious authenticated administrator to store a JavaScript payload using the web interface. This issue is applicable to PAN-OS software on PA-Series and VM-Series firewalls and on…

  • CVE-2015-4162Jun 2, 2015
    risk 0.00cvss epss 0.01

    XML external entity (XXE) vulnerability in the management interface in PAN-OS before 5.0.16, 6.x before 6.0.8, and 6.1.x before 6.1.4 allows remote authenticated administrators to obtain sensitive information via crafted XML data.

  • CVE-2014-3764Jan 6, 2015
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in the web-based device management interface in Palo Alto Networks PAN-OS before 5.0.15, 5.1.x before 5.1.10, and 6.0.x before 6.0.6 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka Ref ID 64563.

Page 12 of 13