CVE-2023-0004
- EPSS 0.72%
- Veröffentlicht 12.04.2023 17:15:07
- Zuletzt bearbeitet 21.11.2024 07:36:22
A local file deletion vulnerability in Palo Alto Networks PAN-OS software enables an authenticated administrator to delete files from the local file system with elevated privileges. These files can include logs and system components that impact the ...
CVE-2023-0005
- EPSS 0.07%
- Veröffentlicht 12.04.2023 17:15:07
- Zuletzt bearbeitet 21.11.2024 07:36:22
A vulnerability in Palo Alto Networks PAN-OS software enables an authenticated administrator to expose the plaintext values of secrets stored in the device configuration and encrypted API keys.
CVE-2022-0030
- EPSS 0.11%
- Veröffentlicht 12.10.2022 17:15:10
- Zuletzt bearbeitet 21.11.2024 06:37:51
An authentication bypass vulnerability in the Palo Alto Networks PAN-OS 8.1 web interface allows a network-based attacker with specific knowledge of the target firewall or Panorama appliance to impersonate an existing PAN-OS administrator and perform...
CVE-2022-0028
- EPSS 4.44%
- Veröffentlicht 10.08.2022 16:15:08
- Zuletzt bearbeitet 07.02.2025 15:03:58
A PAN-OS URL filtering policy misconfiguration could allow a network-based attacker to conduct reflected and amplified TCP denial-of-service (RDoS) attacks. The DoS attack would appear to originate from a Palo Alto Networks PA-Series (hardware), VM-S...
- EPSS 1.21%
- Veröffentlicht 11.05.2022 17:15:09
- Zuletzt bearbeitet 21.11.2024 06:37:50
A vulnerability exists in Palo Alto Networks PAN-OS software that enables an authenticated network-based PAN-OS administrator to upload a specifically created configuration that disrupts system processes and potentially execute arbitrary code with ro...
CVE-2022-0023
- EPSS 0.65%
- Veröffentlicht 13.04.2022 19:15:09
- Zuletzt bearbeitet 21.11.2024 06:37:50
An improper handling of exceptional conditions vulnerability exists in the DNS proxy feature of Palo Alto Networks PAN-OS software that enables a meddler-in-the-middle (MITM) to send specifically crafted traffic to the firewall that causes the servic...
CVE-2022-0022
- EPSS 0.08%
- Veröffentlicht 09.03.2022 18:15:07
- Zuletzt bearbeitet 21.11.2024 06:37:50
Usage of a weak cryptographic algorithm in Palo Alto Networks PAN-OS software where the password hashes of administrator and local user accounts are not created with a sufficient level of computational effort, which allows for password cracking attac...
CVE-2022-0011
- EPSS 0.49%
- Veröffentlicht 10.02.2022 18:15:08
- Zuletzt bearbeitet 21.11.2024 06:37:48
PAN-OS software provides options to exclude specific websites from URL category enforcement and those websites are blocked or allowed (depending on your rules) regardless of their associated URL category. This is done by creating a custom URL categor...
CVE-2021-3059
- EPSS 1.03%
- Veröffentlicht 10.11.2021 17:15:10
- Zuletzt bearbeitet 21.11.2024 06:20:52
An OS command injection vulnerability in the Palo Alto Networks PAN-OS management interface exists when performing dynamic updates. This vulnerability enables a man-in-the-middle attacker to execute arbitrary OS commands to escalate privileges. This ...
CVE-2021-3060
- EPSS 41.02%
- Veröffentlicht 10.11.2021 17:15:10
- Zuletzt bearbeitet 21.11.2024 06:20:52
An OS command injection vulnerability in the Simple Certificate Enrollment Protocol (SCEP) feature of PAN-OS software allows an unauthenticated network-based attacker with specific knowledge of the firewall configuration to execute arbitrary code wit...