VYPR

Pan OS

by Paloaltonetworks

CVEs (258)

  • CVE-2024-3385HigApr 10, 2024
    risk 0.49cvss 7.5epss 0.01

    A packet processing mechanism in Palo Alto Networks PAN-OS software enables a remote attacker to reboot hardware-based firewalls. Repeated attacks eventually cause the firewall to enter maintenance mode, which requires manual intervention to bring the firewall back online. This…

  • CVE-2024-3384HigApr 10, 2024
    risk 0.49cvss 7.5epss 0.01

    A vulnerability in Palo Alto Networks PAN-OS software enables a remote attacker to reboot PAN-OS firewalls when receiving Windows New Technology LAN Manager (NTLM) packets from Windows servers. Repeated attacks eventually cause the firewall to enter maintenance mode, which…

  • CVE-2024-3382HigApr 10, 2024
    risk 0.49cvss 7.5epss 0.01

    A memory leak exists in Palo Alto Networks PAN-OS software that enables an attacker to send a burst of crafted packets through the firewall that eventually prevents the firewall from processing traffic. This issue applies only to PA-5400 Series devices that are running PAN-OS…

  • CVE-2021-3063HigNov 10, 2021
    risk 0.49cvss 7.5epss 0.01

    An improper handling of exceptional conditions vulnerability exists in Palo Alto Networks GlobalProtect portal and gateway interfaces that enables an unauthenticated network-based attacker to send specifically crafted traffic to a GlobalProtect interface that causes the service…

  • CVE-2021-3053HigSep 8, 2021
    risk 0.49cvss 7.5epss 0.01

    An improper handling of exceptional conditions vulnerability exists in the Palo Alto Networks PAN-OS dataplane that enables an unauthenticated network-based attacker to send specifically crafted traffic through the firewall that causes the service to crash. Repeated attempts to…

  • CVE-2020-2022HigNov 12, 2020
    risk 0.49cvss 7.5epss 0.01

    An information exposure vulnerability exists in Palo Alto Networks Panorama software that discloses the token for the Panorama web interface administrator's session to a managed device when the Panorama administrator performs a context switch into that device. This vulnerability…

  • CVE-2020-2041HigSep 9, 2020
    risk 0.49cvss 7.5epss 0.02

    An insecure configuration of the appweb daemon of Palo Alto Networks PAN-OS 8.1 allows a remote unauthenticated user to send a specifically crafted request to the device that causes the appweb service to crash. Repeated attempts to send this request result in denial of service…

  • CVE-2020-2012HigMay 13, 2020
    risk 0.49cvss 7.5epss 0.02

    Improper restriction of XML external entity reference ('XXE') vulnerability in Palo Alto Networks Panorama management service allows remote unauthenticated attackers with network access to the Panorama management interface to read arbitrary files on the system. This issue…

  • CVE-2020-2011HigMay 13, 2020
    risk 0.49cvss 7.5epss 0.02

    An improper input validation vulnerability in the configuration daemon of Palo Alto Networks PAN-OS Panorama allows for a remote unauthenticated user to send a specifically crafted registration request to the device that causes the configuration service to crash. Repeated…

  • CVE-2019-1572HigMar 26, 2019
    risk 0.49cvss 7.5epss 0.02

    PAN-OS 9.0.0 may allow an unauthenticated remote user to access php files.

  • CVE-2017-15942HigDec 11, 2017
    risk 0.49cvss 7.5epss 0.02

    Palo Alto Networks PAN-OS before 6.1.19, 7.0.x before 7.0.19, 7.1.x before 7.1.13, and 8.0.x before 8.0.6 allows remote attackers to cause a denial of service via vectors related to the management interface.

  • CVE-2016-3656HigApr 12, 2016
    risk 0.49cvss 7.5epss 0.02

    The GlobalProtect Portal in Palo Alto Networks PAN-OS before 5.0.18, 6.0.x before 6.0.13, 6.1.x before 6.1.10, and 7.0.x before 7.0.5H2 allows remote attackers to cause a denial of service (service crash) via a crafted request.

  • CVE-2024-3383HigApr 10, 2024
    risk 0.48cvss 7.4epss 0.01

    A vulnerability in how Palo Alto Networks PAN-OS software processes data received from Cloud Identity Engine (CIE) agents enables modification of User-ID groups. This impacts user access to network resources where users may be inappropriately denied or allowed access to…

  • CVE-2026-0286HigJul 9, 2026
    risk 0.47cvss 7.2epss 0.01

    A command injection vulnerability in the management plane of Palo Alto Networks PAN-OS® software enables an authenticated administrator to execute arbitrary OS commands as root. The security risk posed by this issue is significantly minimized when CLI access is restricted to…

  • CVE-2026-0283HigJul 9, 2026
    risk 0.47cvss 7.2epss 0.00

    An authentication bypass vulnerability in Large Scale VPN ( LSVPN) functionality of Palo Alto Networks PAN-OS software allows an attacker with network access to bypass security restrictions and establish an unauthorized site-to-site VPN connection. Panorama, Cloud NGFW, and…

  • CVE-2026-0280HigJul 9, 2026
    risk 0.47cvss 7.2epss 0.00

    An IPv6 packet processing vulnerability in the dataplane of Palo Alto Networks PAN-OS® software enables an unauthenticated attacker to bypass firewall security policy enforcement, allowing network traffic that should be blocked to reach protected services. Cloud NGFW and…

  • CVE-2026-0261HigMay 13, 2026
    risk 0.47cvss 7.2epss 0.01

    Multiple command injection vulnerabilities in Palo Alto Networks PAN-OS® software enable an authenticated administrator to bypass system restrictions and run arbitrary commands as a root user. To be able to exploit this issue, the user must have access to the PAN-OS CLI or Web…

  • CVE-2025-4615HigOct 9, 2025
    risk 0.47cvss 7.2epss 0.01

    An improper input neutralization vulnerability in the management web interface of the Palo Alto Networks PAN-OS® software enables an authenticated administrator to bypass system restrictions and execute arbitrary commands. The security risk posed by this issue is significantly…

  • CVE-2025-4231HigJun 13, 2025
    risk 0.47cvss 7.2epss 0.01

    A command injection vulnerability in Palo Alto Networks PAN-OS® enables an authenticated administrative user to perform actions as the root user. The attacker must have network access to the management web interface and successfully authenticate to exploit this issue. Cloud…

  • CVE-2024-8686HigSep 11, 2024
    risk 0.47cvss 7.2epss 0.01

    A command injection vulnerability in Palo Alto Networks PAN-OS software enables an authenticated administrator to bypass system restrictions and run arbitrary commands as root on the firewall.

Page 5 of 13