VYPR

Prisma Access Agent

by Paloaltonetworks

CVEs (84)

  • CVE-2023-0007MedMay 10, 2023
    risk 0.42cvss 6.5epss 0.00

    A cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS software on Panorama appliances enables an authenticated read-write administrator to store a JavaScript payload in the web interface that will execute in the context of another administrator’s browser when…

  • CVE-2023-0004MedApr 12, 2023
    risk 0.42cvss 6.5epss 0.01

    A local file deletion vulnerability in Palo Alto Networks PAN-OS software enables an authenticated administrator to delete files from the local file system with elevated privileges. These files can include logs and system components that impact the integrity and availability of…

  • CVE-2022-0011MedFeb 10, 2022
    risk 0.42cvss 6.5epss 0.01

    PAN-OS software provides options to exclude specific websites from URL category enforcement and those websites are blocked or allowed (depending on your rules) regardless of their associated URL category. This is done by creating a custom URL category list or by using an…

  • CVE-2021-3061MedNov 10, 2021
    risk 0.42cvss 6.4epss 0.01

    An OS command injection vulnerability in the Palo Alto Networks PAN-OS command line interface (CLI) enables an authenticated administrator with access to the CLI to execute arbitrary OS commands to escalate privileges. This issue impacts: PAN-OS 8.1 versions earlier than PAN-OS…

  • CVE-2024-0009MedFeb 14, 2024
    risk 0.41cvss 6.3epss 0.00

    An improper verification vulnerability in the GlobalProtect gateway feature of Palo Alto Networks PAN-OS software enables a malicious user with stolen credentials to establish a VPN connection from an unauthorized IP address.

  • CVE-2025-0104MedJan 11, 2025
    risk 0.40cvss 6.1epss 0.00

    A reflected cross-site scripting (XSS) vulnerability in Palo Alto Networks Expedition enables attackers to execute malicious JavaScript code in the context of an authenticated Expedition user’s browser if that authenticated user clicks a malicious link that allows phishing…

  • CVE-2024-5913MedJul 10, 2024
    risk 0.40cvss 6.1epss 0.00

    An improper input validation vulnerability in Palo Alto Networks PAN-OS software enables an attacker with the ability to tamper with the physical file system to elevate privileges.

  • CVE-2026-0294MedAug 13, 2026
    risk 0.39cvss epss 0.00

    A privilege escalation (PE) vulnerability in the Palo Alto Networks Prisma® Access Agent app on Windows and macOS devices enables a local user to execute code with elevated privileges. The Prisma Access Agent on Linux, iOS, Android, and ChromeOS is not affected.

  • CVE-2024-2552MedNov 14, 2024
    risk 0.39cvss 6.0epss 0.00

    A command injection vulnerability in Palo Alto Networks PAN-OS software enables an authenticated administrator to bypass system restrictions in the management plane and delete files on the firewall.

  • CVE-2026-0277MedJul 9, 2026
    risk 0.38cvss 5.9epss 0.00

    An improper certificate validation vulnerability in the Prisma® Access Agent for iOS enables an attacker to perform a man-in-the-middle (MitM) attack to intercept VPN traffic. The Prisma Access Agent on Windows, macOS, Linux, Android and ChromeOS are not affected.

  • CVE-2026-0271MedJun 10, 2026
    risk 0.38cvss epss 0.00

    A privilege escalation (PE) vulnerability in the Palo Alto Networks Prisma Access Agent app on Linux devices enables a local user to execute code with elevated privileges. This does not impact Prisma Access Agent on Windows, macOS, iOS, Android, or ChromeOS.

  • CVE-2026-0248MedMay 13, 2026
    risk 0.38cvss 5.9epss 0.00

    An improper certificate validation vulnerability in the Prisma Access Agent® for Android and Chrome OS enables an attacker to perform a man-in-the-middle (MitM) attack to intercept VPN traffic. By presenting a certificate for any domain issued by a trusted Certificate…

  • CVE-2022-0023MedApr 13, 2022
    risk 0.38cvss 5.9epss 0.01

    An improper handling of exceptional conditions vulnerability exists in the DNS proxy feature of Palo Alto Networks PAN-OS software that enables a meddler-in-the-middle (MITM) to send specifically crafted traffic to the firewall that causes the service to restart unexpectedly.…

  • CVE-2026-0293MedAug 13, 2026
    risk 0.36cvss epss 0.00

    A vulnerability in Palo Alto Networks Prisma® Access Agent on Windows enables a local attacker with administrator privileges to bypass the anti-tamper protection, enabling unauthorized access to protected processes and files. The Prisma Access Agent on Linux, macOS, iOS,…

  • CVE-2026-0245MedMay 13, 2026
    risk 0.36cvss 5.5epss 0.00

    Multiple information disclosure vulnerabilities in Prisma Access Agent® allow a local user to access sensitive configuration data and credentials. The Prisma Access Agent on Linux, ChromeOS, Android, and iOS are not affected.

  • CVE-2023-6795MedDec 13, 2023
    risk 0.36cvss 5.5epss 0.01

    An OS command injection vulnerability in Palo Alto Networks PAN-OS software enables an authenticated administrator to disrupt system processes and potentially execute arbitrary code with limited privileges on the firewall.

  • CVE-2023-6794MedDec 13, 2023
    risk 0.36cvss 5.5epss 0.01

    An arbitrary file upload vulnerability in Palo Alto Networks PAN-OS software enables an authenticated read-write administrator with access to the web interface to disrupt system processes and potentially execute arbitrary code with limited privileges on the firewall.

  • CVE-2023-6792MedDec 13, 2023
    risk 0.36cvss 5.5epss 0.01

    An OS command injection vulnerability in the XML API of Palo Alto Networks PAN-OS software enables an authenticated API user to disrupt system processes and potentially execute arbitrary code with limited privileges on the firewall.

  • CVE-2023-38046MedJul 12, 2023
    risk 0.36cvss 5.5epss 0.00

    A vulnerability exists in Palo Alto Networks PAN-OS software that enables an authenticated administrator with the privilege to commit a specifically created configuration to read local files and resources from the system.

  • CVE-2023-0010MedJun 14, 2023
    risk 0.35cvss 5.4epss 0.00

    A reflected cross-site scripting (XSS) vulnerability in the Captive Portal feature of Palo Alto Networks PAN-OS software can allow a JavaScript payload to be executed in the context of an authenticated Captive Portal user’s browser when they click on a specifically crafted…