CVE-2020-1996
- EPSS 0.7%
- Veröffentlicht 13.05.2020 19:15:12
- Zuletzt bearbeitet 21.11.2024 05:11:48
A missing authorization vulnerability in the management server component of PAN-OS Panorama allows a remote unauthenticated user to inject messages into the management server ms.log file. This vulnerability can be leveraged to obfuscate an ongoing at...
CVE-2020-1997
- EPSS 0.28%
- Veröffentlicht 13.05.2020 19:15:12
- Zuletzt bearbeitet 21.11.2024 05:11:48
An open redirection vulnerability in the GlobalProtect component of Palo Alto Networks PAN-OS allows an attacker to specify an arbitrary redirection target away from the trusted GlobalProtect gateway. If the user then successfully authenticates it wi...
CVE-2020-1998
- EPSS 0.22%
- Veröffentlicht 13.05.2020 19:15:12
- Zuletzt bearbeitet 21.11.2024 05:11:49
An improper authorization vulnerability in PAN-OS that mistakenly uses the permissions of local linux users instead of the intended SAML permissions of the account when the username is shared for the purposes of SSO authentication. This can result in...
CVE-2020-2001
- EPSS 1.53%
- Veröffentlicht 13.05.2020 19:15:12
- Zuletzt bearbeitet 21.11.2024 05:24:24
An external control of path and data vulnerability in the Palo Alto Networks PAN-OS Panorama XSLT processing logic that allows an unauthenticated user with network access to PAN-OS management interface to write attacker supplied file on the system an...
CVE-2020-2002
- EPSS 0.58%
- Veröffentlicht 13.05.2020 19:15:12
- Zuletzt bearbeitet 21.11.2024 05:24:24
An authentication bypass by spoofing vulnerability exists in the authentication daemon and User-ID components of Palo Alto Networks PAN-OS by failing to verify the integrity of the Kerberos key distribution center (KDC) before authenticating users. T...
- EPSS 1.38%
- Veröffentlicht 08.04.2020 19:15:14
- Zuletzt bearbeitet 21.11.2024 05:11:47
A stack-based buffer overflow vulnerability in the management server component of PAN-OS allows an authenticated user to upload a corrupted PAN-OS configuration and potentially execute code with root privileges. This issue affects Palo Alto Networks ...
CVE-2020-1992
- EPSS 2.05%
- Veröffentlicht 08.04.2020 19:15:14
- Zuletzt bearbeitet 21.11.2024 05:11:48
A format string vulnerability in the Varrcvr daemon of PAN-OS on PA-7000 Series devices with a Log Forwarding Card (LFC) allows remote attackers to crash the daemon creating a denial of service condition or potentially execute code with root privileg...
CVE-2020-1978
- EPSS 0.09%
- Veröffentlicht 08.04.2020 19:15:13
- Zuletzt bearbeitet 21.11.2024 05:11:46
TechSupport files generated on Palo Alto Networks VM Series firewalls for Microsoft Azure platform configured with high availability (HA) inadvertently collect Azure dashboard service account credentials. These credentials are equivalent to the crede...
CVE-2020-1979
- EPSS 0.24%
- Veröffentlicht 11.03.2020 19:15:13
- Zuletzt bearbeitet 21.11.2024 05:11:46
A format string vulnerability in the PAN-OS log daemon (logd) on Panorama allows a network based attacker with knowledge of registered firewall devices and access to Panorama management interfaces to execute arbitrary code, bypassing the restricted s...
CVE-2020-1980
- EPSS 0.27%
- Veröffentlicht 11.03.2020 19:15:13
- Zuletzt bearbeitet 21.11.2024 05:11:46
A shell command injection vulnerability in the PAN-OS CLI allows a local authenticated user to escape the restricted shell and escalate privileges. This issue affects only PAN-OS 8.1 versions earlier than PAN-OS 8.1.13. This issue does not affect PAN...