VYPR

Cloud Ngfw

by Paloaltonetworks

CVEs (62)

  • CVE-2024-3384HigApr 10, 2024
    risk 0.49cvss 7.5epss 0.01

    A vulnerability in Palo Alto Networks PAN-OS software enables a remote attacker to reboot PAN-OS firewalls when receiving Windows New Technology LAN Manager (NTLM) packets from Windows servers. Repeated attacks eventually cause the firewall to enter maintenance mode, which…

  • CVE-2024-3382HigApr 10, 2024
    risk 0.49cvss 7.5epss 0.01

    A memory leak exists in Palo Alto Networks PAN-OS software that enables an attacker to send a burst of crafted packets through the firewall that eventually prevents the firewall from processing traffic. This issue applies only to PA-5400 Series devices that are running PAN-OS…

  • CVE-2024-3383HigApr 10, 2024
    risk 0.48cvss 7.4epss 0.01

    A vulnerability in how Palo Alto Networks PAN-OS software processes data received from Cloud Identity Engine (CIE) agents enables modification of User-ID groups. This impacts user access to network resources where users may be inappropriately denied or allowed access to…

  • CVE-2025-4231HigJun 13, 2025
    risk 0.47cvss 7.2epss 0.01

    A command injection vulnerability in Palo Alto Networks PAN-OS® enables an authenticated administrative user to perform actions as the root user. The attacker must have network access to the management web interface and successfully authenticate to exploit this issue. Cloud…

  • CVE-2024-8686HigSep 11, 2024
    risk 0.47cvss 7.2epss 0.01

    A command injection vulnerability in Palo Alto Networks PAN-OS software enables an authenticated administrator to bypass system restrictions and run arbitrary commands as root on the firewall.

  • CVE-2024-8691HigSep 11, 2024
    risk 0.46cvss 7.1epss 0.00

    A vulnerability in the GlobalProtect portal in Palo Alto Networks PAN-OS software enables a malicious authenticated GlobalProtect user to impersonate another GlobalProtect user. Active GlobalProtect users impersonated by an attacker who is exploiting this vulnerability are…

  • CVE-2024-8687HigSep 11, 2024
    risk 0.46cvss 7.1epss 0.00

    An information exposure vulnerability exists in Palo Alto Networks PAN-OS software that enables a GlobalProtect end user to learn both the configured GlobalProtect uninstall password and the configured disable or disconnect passcode. After the password or passcode is known, end…

  • CVE-2024-0007MedFeb 14, 2024
    risk 0.44cvss 6.8epss 0.00

    A cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS software enables a malicious authenticated read-write administrator to store a JavaScript payload using the web interface on Panorama appliances. This enables the impersonation of another authenticated…

  • CVE-2024-0008MedFeb 14, 2024
    risk 0.43cvss 6.6epss 0.01

    Web sessions in the management interface in Palo Alto Networks PAN-OS software do not expire in certain situations, making it susceptible to unauthorized access.

  • CVE-2024-5919MedNov 14, 2024
    risk 0.42cvss 6.5epss 0.00

    A blind XML External Entities (XXE) injection vulnerability in the Palo Alto Networks PAN-OS software enables an authenticated attacker to exfiltrate arbitrary files from firewalls to an attacker controlled server. This attack requires network access to the firewall management…

  • CVE-2023-0007MedMay 10, 2023
    risk 0.42cvss 6.5epss 0.00

    A cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS software on Panorama appliances enables an authenticated read-write administrator to store a JavaScript payload in the web interface that will execute in the context of another administrator’s browser when…

  • CVE-2023-0004MedApr 12, 2023
    risk 0.42cvss 6.5epss 0.01

    A local file deletion vulnerability in Palo Alto Networks PAN-OS software enables an authenticated administrator to delete files from the local file system with elevated privileges. These files can include logs and system components that impact the integrity and availability of…

  • CVE-2024-0009MedFeb 14, 2024
    risk 0.41cvss 6.3epss 0.00

    An improper verification vulnerability in the GlobalProtect gateway feature of Palo Alto Networks PAN-OS software enables a malicious user with stolen credentials to establish a VPN connection from an unauthorized IP address.

  • CVE-2025-0104MedJan 11, 2025
    risk 0.40cvss 6.1epss 0.00

    A reflected cross-site scripting (XSS) vulnerability in Palo Alto Networks Expedition enables attackers to execute malicious JavaScript code in the context of an authenticated Expedition user’s browser if that authenticated user clicks a malicious link that allows phishing…

  • CVE-2024-5913MedJul 10, 2024
    risk 0.40cvss 6.1epss 0.00

    An improper input validation vulnerability in Palo Alto Networks PAN-OS software enables an attacker with the ability to tamper with the physical file system to elevate privileges.

  • CVE-2024-2552MedNov 14, 2024
    risk 0.39cvss 6.0epss 0.00

    A command injection vulnerability in Palo Alto Networks PAN-OS software enables an authenticated administrator to bypass system restrictions in the management plane and delete files on the firewall.

  • CVE-2023-6795MedDec 13, 2023
    risk 0.36cvss 5.5epss 0.01

    An OS command injection vulnerability in Palo Alto Networks PAN-OS software enables an authenticated administrator to disrupt system processes and potentially execute arbitrary code with limited privileges on the firewall.

  • CVE-2023-6794MedDec 13, 2023
    risk 0.36cvss 5.5epss 0.01

    An arbitrary file upload vulnerability in Palo Alto Networks PAN-OS software enables an authenticated read-write administrator with access to the web interface to disrupt system processes and potentially execute arbitrary code with limited privileges on the firewall.

  • CVE-2023-6792MedDec 13, 2023
    risk 0.36cvss 5.5epss 0.01

    An OS command injection vulnerability in the XML API of Palo Alto Networks PAN-OS software enables an authenticated API user to disrupt system processes and potentially execute arbitrary code with limited privileges on the firewall.

  • CVE-2023-38046MedJul 12, 2023
    risk 0.36cvss 5.5epss 0.00

    A vulnerability exists in Palo Alto Networks PAN-OS software that enables an authenticated administrator with the privilege to commit a specifically created configuration to read local files and resources from the system.