VYPR

Prisma Access Agent

by Paloaltonetworks

CVEs (84)

  • CVE-2026-0246HigMay 13, 2026
    risk 0.51cvss 7.8epss 0.00

    A vulnerability with a privilege management mechanism in the Palo Alto Networks Prisma Access Agent® enables a locally authenticated non-administrative user to escalate their privileges to root on macOS and Linux or NT AUTHORITY\SYSTEM on Windows. This allows the user to…

  • CVE-2026-0227HigJan 15, 2026
    risk 0.49cvss 7.5epss 0.01

    A vulnerability in Palo Alto Networks PAN-OS software enables an unauthenticated attacker to cause a denial of service (DoS) to the firewall. Repeated attempts to trigger this issue results in the firewall entering into maintenance mode.

  • CVE-2025-0130HigMay 14, 2025
    risk 0.49cvss 7.5epss 0.00

    A missing exception check in Palo Alto Networks PAN-OS® software with the web proxy feature enabled allows an unauthenticated attacker to send a burst of maliciously crafted packets that causes the firewall to become unresponsive and eventually reboot. Repeated successful…

  • CVE-2025-0114HigMar 12, 2025
    risk 0.49cvss 7.5epss 0.00

    A Denial of Service (DoS) vulnerability in the GlobalProtect feature of Palo Alto Networks PAN-OS software enables an unauthenticated attacker to render the service unavailable by sending a large number of specially crafted packets over a period of time. This issue affects both…

  • CVE-2024-2551HigNov 14, 2024
    risk 0.49cvss 7.5epss 0.00

    A null pointer dereference vulnerability in Palo Alto Networks PAN-OS software enables an unauthenticated attacker to stop a core system service on the firewall by sending a crafted packet through the data plane that causes a denial of service (DoS) condition. Repeated attempts…

  • CVE-2024-2550HigNov 14, 2024
    risk 0.49cvss 7.5epss 0.01

    A null pointer dereference vulnerability in the GlobalProtect gateway in Palo Alto Networks PAN-OS software enables an unauthenticated attacker to stop the GlobalProtect service on the firewall by sending a specially crafted packet that causes a denial of service (DoS)…

  • CVE-2024-9468HigOct 9, 2024
    risk 0.49cvss 7.5epss 0.00

    A memory corruption vulnerability in Palo Alto Networks PAN-OS software allows an unauthenticated attacker to crash PAN-OS due to a crafted packet through the data plane, resulting in a denial of service (DoS) condition. Repeated attempts to trigger this condition will result in…

  • CVE-2024-3385HigApr 10, 2024
    risk 0.49cvss 7.5epss 0.01

    A packet processing mechanism in Palo Alto Networks PAN-OS software enables a remote attacker to reboot hardware-based firewalls. Repeated attacks eventually cause the firewall to enter maintenance mode, which requires manual intervention to bring the firewall back online. This…

  • CVE-2024-3384HigApr 10, 2024
    risk 0.49cvss 7.5epss 0.01

    A vulnerability in Palo Alto Networks PAN-OS software enables a remote attacker to reboot PAN-OS firewalls when receiving Windows New Technology LAN Manager (NTLM) packets from Windows servers. Repeated attacks eventually cause the firewall to enter maintenance mode, which…

  • CVE-2024-3382HigApr 10, 2024
    risk 0.49cvss 7.5epss 0.01

    A memory leak exists in Palo Alto Networks PAN-OS software that enables an attacker to send a burst of crafted packets through the firewall that eventually prevents the firewall from processing traffic. This issue applies only to PA-5400 Series devices that are running PAN-OS…

  • CVE-2021-3063HigNov 10, 2021
    risk 0.49cvss 7.5epss 0.01

    An improper handling of exceptional conditions vulnerability exists in Palo Alto Networks GlobalProtect portal and gateway interfaces that enables an unauthenticated network-based attacker to send specifically crafted traffic to a GlobalProtect interface that causes the service…

  • CVE-2024-3383HigApr 10, 2024
    risk 0.48cvss 7.4epss 0.01

    A vulnerability in how Palo Alto Networks PAN-OS software processes data received from Cloud Identity Engine (CIE) agents enables modification of User-ID groups. This impacts user access to network resources where users may be inappropriately denied or allowed access to…

  • CVE-2025-4231HigJun 13, 2025
    risk 0.47cvss 7.2epss 0.01

    A command injection vulnerability in Palo Alto Networks PAN-OS® enables an authenticated administrative user to perform actions as the root user. The attacker must have network access to the management web interface and successfully authenticate to exploit this issue. Cloud…

  • CVE-2024-8686HigSep 11, 2024
    risk 0.47cvss 7.2epss 0.01

    A command injection vulnerability in Palo Alto Networks PAN-OS software enables an authenticated administrator to bypass system restrictions and run arbitrary commands as root on the firewall.

  • CVE-2024-8691HigSep 11, 2024
    risk 0.46cvss 7.1epss 0.00

    A vulnerability in the GlobalProtect portal in Palo Alto Networks PAN-OS software enables a malicious authenticated GlobalProtect user to impersonate another GlobalProtect user. Active GlobalProtect users impersonated by an attacker who is exploiting this vulnerability are…

  • CVE-2024-8687HigSep 11, 2024
    risk 0.46cvss 7.1epss 0.00

    An information exposure vulnerability exists in Palo Alto Networks PAN-OS software that enables a GlobalProtect end user to learn both the configured GlobalProtect uninstall password and the configured disable or disconnect passcode. After the password or passcode is known, end…

  • CVE-2024-0007MedFeb 14, 2024
    risk 0.44cvss 6.8epss 0.00

    A cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS software enables a malicious authenticated read-write administrator to store a JavaScript payload using the web interface on Panorama appliances. This enables the impersonation of another authenticated…

  • CVE-2025-4619MedNov 13, 2025
    risk 0.43cvss epss 0.01

    A denial-of-service (DoS) vulnerability in Palo Alto Networks PAN-OS software enables an unauthenticated attacker to reboot a firewall by sending a specially crafted packet through the dataplane. Repeated attempts to initiate a reboot causes the firewall to enter maintenance…

  • CVE-2024-0008MedFeb 14, 2024
    risk 0.43cvss 6.6epss 0.01

    Web sessions in the management interface in Palo Alto Networks PAN-OS software do not expire in certain situations, making it susceptible to unauthorized access.

  • CVE-2024-5919MedNov 14, 2024
    risk 0.42cvss 6.5epss 0.00

    A blind XML External Entities (XXE) injection vulnerability in the Palo Alto Networks PAN-OS software enables an authenticated attacker to exfiltrate arbitrary files from firewalls to an attacker controlled server. This attack requires network access to the firewall management…

Page 2 of 5