7.2

CVE-2026-0310

Medienbericht

PAN-OS: Buffer Overflow Vulnerability via XML Processing

A buffer overflow vulnerability in the XML processing functionality of Palo Alto Networks PAN-OS® software enables an unauthenticated attacker with network access to the management web or dataplane interface to cause a denial of service (DoS) condition on VM-Series firewalls or execute arbitrary code with root privileges on the PA-Series firewalls.

The security risk posed by this issue is minimized when the management interface is restricted to only trusted internal IP addresses according to our recommended  best practice deployment guidelines https://live.paloaltonetworks.com/t5/community-blogs/tips-amp-tricks-how-to-secure-the-management-access-of-your-palo/ba-p/464431 . 

Panorama is impacted by this vulnerability.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerPalo Alto Networks
≫
Produkt Cloud NGFW
Default Statusunaffected
Version All
Status affected
HerstellerPalo Alto Networks
≫
Produkt PAN-OS
Default Statusunaffected
Version 12.2.0
Version < 12.2.3
Status affected
Version 12.1.0
Version < 12.1.4-h10
Status affected
Version 11.2.0
Version < 11.2.4-h21
Status affected
Version 11.1.0
Version < 11.1.4-h36
Status affected
Version 10.2.0
Version < 10.2.7-h37
Status affected
HerstellerPalo Alto Networks
≫
Produkt Prisma Access
Default Statusunaffected
Version 12.1.0
Version < 12.1.4-h10
Status unaffected
Version 11.2.0
Version < 11.2.4-h21
Status affected
Version 10.2.0
Version < 10.2.7-h37
Status affected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.34% 0.268
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
psirt@paloaltonetworks.com 7.2 0 0
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:D/RE:M/U:Red
CWE-787 Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.

Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
VulnDex Intel
Media Report
21.09.2026 16:52
https://security.paloaltonetworks.com/CVE-2026-0310