VYPR

Prisma Access Agent

by Paloaltonetworks

CVEs (84)

  • CVE-2024-3400CriKEVApr 12, 2024
    risk 0.94cvss 10.0epss 1.00

    A command injection as a result of arbitrary file creation vulnerability in the GlobalProtect feature of Palo Alto Networks PAN-OS software for specific PAN-OS versions and distinct feature configurations may enable an unauthenticated attacker to execute arbitrary code with root…

  • CVE-2024-0012CriKEVNov 18, 2024
    risk 0.93cvss 9.8epss 1.00

    An authentication bypass in Palo Alto Networks PAN-OS software enables an unauthenticated attacker with network access to the management web interface to gain PAN-OS administrator privileges to perform administrative actions, tamper with the configuration, or exploit other…

  • CVE-2020-2021CriKEVJun 29, 2020
    risk 0.83cvss 10.0epss 0.04

    When Security Assertion Markup Language (SAML) authentication is enabled and the 'Validate Identity Provider Certificate' option is disabled (unchecked), improper verification of signatures in PAN-OS SAML authentication enables an unauthenticated network-based attacker to access…

  • CVE-2025-0108CriKEVFeb 12, 2025
    risk 0.79cvss 9.1epss 0.98

    An authentication bypass in the Palo Alto Networks PAN-OS software enables an unauthenticated attacker with network access to the management web interface to bypass the authentication otherwise required by the PAN-OS management web interface and invoke certain PHP scripts. While…

  • CVE-2024-9474HigKEVNov 18, 2024
    risk 0.75cvss 7.2epss 0.95

    A privilege escalation vulnerability in Palo Alto Networks PAN-OS software allows a PAN-OS administrator with access to the management web interface to perform actions on the firewall with root privileges. Cloud NGFW and Prisma Access are not impacted by this vulnerability.

  • CVE-2025-0107CriJan 11, 2025
    risk 0.70cvss 9.8epss 0.79

    An OS command injection vulnerability in Palo Alto Networks Expedition enables an unauthenticated attacker to run arbitrary OS commands as the www-data user in Expedition, which results in the disclosure of usernames, cleartext passwords, device configurations, and device API…

  • CVE-2022-0028HigKEVAug 10, 2022
    risk 0.68cvss 8.6epss 0.02

    A PAN-OS URL filtering policy misconfiguration could allow a network-based attacker to conduct reflected and amplified TCP denial-of-service (RDoS) attacks. The DoS attack would appear to originate from a Palo Alto Networks PA-Series (hardware), VM-Series (virtual) and CN-Series…

  • CVE-2021-3064CriNov 10, 2021
    risk 0.65cvss 9.8epss 0.19

    A memory corruption vulnerability exists in Palo Alto Networks GlobalProtect portal and gateway interfaces that enables an unauthenticated network-based attacker to disrupt system processes and potentially execute arbitrary code with root privileges. The attacker must have…

  • CVE-2025-0105CriJan 11, 2025
    risk 0.60cvss 9.1epss 0.13

    An arbitrary file deletion vulnerability in Palo Alto Networks Expedition enables an unauthenticated attacker to delete arbitrary files accessible to the www-data user on the host filesystem.

  • CVE-2025-0103HigJan 11, 2025
    risk 0.57cvss 8.8epss 0.01

    An SQL injection vulnerability in Palo Alto Networks Expedition enables an authenticated attacker to reveal Expedition database contents, such as password hashes, usernames, device configurations, and device API keys. This vulnerability also enables attackers to create and read…

  • CVE-2023-6790HigDec 13, 2023
    risk 0.57cvss 8.8epss 0.01

    A DOM-Based cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS software enables a remote attacker to execute a JavaScript payload in the context of an administrator’s browser when they view a specifically crafted link to the PAN-OS web interface.

  • CVE-2021-3058HigNov 10, 2021
    risk 0.57cvss 8.8epss 0.02

    An OS command injection vulnerability in the Palo Alto Networks PAN-OS web interface enables an authenticated administrator with permissions to use XML API the ability to execute arbitrary OS commands to escalate privileges. This issue impacts: PAN-OS 8.1 versions earlier than…

  • CVE-2021-3056HigNov 10, 2021
    risk 0.57cvss 8.8epss 0.01

    A memory corruption vulnerability in Palo Alto Networks PAN-OS GlobalProtect Clientless VPN enables an authenticated attacker to execute arbitrary code with root user privileges during SAML authentication. This issue impacts: PAN-OS 8.1 versions earlier than PAN-OS 8.1.20;…

  • CVE-2021-3060HigNov 10, 2021
    risk 0.55cvss 8.1epss 0.34

    An OS command injection vulnerability in the Simple Certificate Enrollment Protocol (SCEP) feature of PAN-OS software allows an unauthenticated network-based attacker with specific knowledge of the firewall configuration to execute arbitrary code with root user privileges. The…

  • CVE-2025-0111MedKEVFeb 12, 2025
    risk 0.54cvss 6.5epss 0.02

    An authenticated file read vulnerability in the Palo Alto Networks PAN-OS software enables an authenticated attacker with network access to the management web interface to read files on the PAN-OS filesystem that are readable by the “nobody” user. You can greatly reduce the…

  • CVE-2022-0030HigOct 12, 2022
    risk 0.53cvss 8.1epss 0.01

    An authentication bypass vulnerability in the Palo Alto Networks PAN-OS 8.1 web interface allows a network-based attacker with specific knowledge of the target firewall or Panorama appliance to impersonate an existing PAN-OS administrator and perform privileged actions.

  • CVE-2021-3062HigNov 10, 2021
    risk 0.53cvss 8.1epss 0.01

    An improper access control vulnerability in PAN-OS software enables an attacker with authenticated access to GlobalProtect portals and gateways to connect to the EC2 instance metadata endpoint for VM-Series firewalls hosted on Amazon AWS. Exploitation of this vulnerability…

  • CVE-2021-3059HigNov 10, 2021
    risk 0.53cvss 8.1epss 0.02

    An OS command injection vulnerability in the Palo Alto Networks PAN-OS management interface exists when performing dynamic updates. This vulnerability enables a man-in-the-middle attacker to execute arbitrary OS commands to escalate privileges. This issue impacts: PAN-OS 8.1…

  • CVE-2026-0278HigJul 9, 2026
    risk 0.51cvss 7.8epss 0.00

    Multiple protection mechanism failures in the Prisma Access Agent Data Loss Prevention (DLP) component for Windows allow a local user to bypass DLP policy enforcement controls. The Prisma Access Agent on macOS is not affected.

  • CVE-2026-0247HigMay 13, 2026
    risk 0.51cvss 7.8epss 0.00

    Multiple authorization bypass vulnerabilities in the Endpoint DLP component of Prisma Access Agent® allow a local attacker to bypass authentication controls and execute privileged operations.

Page 1 of 5