7.2
CVE-2026-0310
- EPSS 0.34%
- Veröffentlicht 10.09.2026 05:21:28
- Zuletzt bearbeitet 11.09.2026 04:17:13
- Erkennungen
PAN-OS: Buffer Overflow Vulnerability via XML Processing
A buffer overflow vulnerability in the XML processing functionality of Palo Alto Networks PAN-OS® software enables an unauthenticated attacker with network access to the management web or dataplane interface to cause a denial of service (DoS) condition on VM-Series firewalls or execute arbitrary code with root privileges on the PA-Series firewalls. The security risk posed by this issue is minimized when the management interface is restricted to only trusted internal IP addresses according to our recommended best practice deployment guidelines https://live.paloaltonetworks.com/t5/community-blogs/tips-amp-tricks-how-to-secure-the-management-access-of-your-palo/ba-p/464431 . Panorama is impacted by this vulnerability.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerPalo Alto Networks
≫
Produkt
Cloud NGFW
Default Statusunaffected
Version
All
Status
affected
HerstellerPalo Alto Networks
≫
Produkt
PAN-OS
Default Statusunaffected
Version
12.2.0
Version <
12.2.3
Status
affected
Version
12.1.0
Version <
12.1.4-h10
Status
affected
Version
11.2.0
Version <
11.2.4-h21
Status
affected
Version
11.1.0
Version <
11.1.4-h36
Status
affected
Version
10.2.0
Version <
10.2.7-h37
Status
affected
HerstellerPalo Alto Networks
≫
Produkt
Prisma Access
Default Statusunaffected
Version
12.1.0
Version <
12.1.4-h10
Status
unaffected
Version
11.2.0
Version <
11.2.4-h21
Status
affected
Version
10.2.0
Version <
10.2.7-h37
Status
affected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.34% | 0.268 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| psirt@paloaltonetworks.com | 7.2 | 0 | 0 |
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:D/RE:M/U:Red
|
CWE-787 Out-of-bounds Write
The product writes data past the end, or before the beginning, of the intended buffer.
Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
https://security.paloaltonetworks.com/CVE-2026-0310