CVE-2021-3045
- EPSS 0.6%
- Published 11.08.2021 17:15:07
- Last modified 21.11.2024 06:20:50
An OS command argument injection vulnerability in the Palo Alto Networks PAN-OS web interface enables an authenticated administrator to read any arbitrary file from the file system. This issue impacts: PAN-OS 8.1 versions earlier than PAN-OS 8.1.19; ...
CVE-2021-3046
- EPSS 0.25%
- Published 11.08.2021 17:15:07
- Last modified 21.11.2024 06:20:50
An improper authentication vulnerability exists in Palo Alto Networks PAN-OS software that enables a SAML authenticated attacker to impersonate any other user in the GlobalProtect Portal and GlobalProtect Gateway when they are configured to use SAML ...
CVE-2021-3047
- EPSS 0.28%
- Published 11.08.2021 17:15:07
- Last modified 21.11.2024 06:20:50
A cryptographically weak pseudo-random number generator (PRNG) is used during authentication to the Palo Alto Networks PAN-OS web interface. This enables an authenticated attacker, with the capability to observe their own authentication secrets over ...
CVE-2021-3048
- EPSS 0.78%
- Published 11.08.2021 17:15:07
- Last modified 21.11.2024 06:20:50
Certain invalid URL entries contained in an External Dynamic List (EDL) cause the Device Server daemon (devsrvr) to stop responding. This condition causes subsequent commits on the firewall to fail and prevents administrators from performing commits ...
- EPSS 1.86%
- Published 11.08.2021 17:15:07
- Last modified 21.11.2024 06:20:50
An OS command injection vulnerability in the Palo Alto Networks PAN-OS web interface enables an authenticated administrator to execute arbitrary OS commands to escalate privileges. This issue impacts: PAN-OS 9.0 version 9.0.10 through PAN-OS 9.0.14; ...
CVE-2021-3036
- EPSS 0.14%
- Published 20.04.2021 04:15:12
- Last modified 21.11.2024 06:20:48
An information exposure through log file vulnerability exists in Palo Alto Networks PAN-OS software where secrets in PAN-OS XML API requests are logged in cleartext to the web server logs when the API is used incorrectly. This vulnerability applies o...
CVE-2021-3037
- EPSS 0.16%
- Published 20.04.2021 04:15:12
- Last modified 21.11.2024 06:20:48
An information exposure through log file vulnerability exists in Palo Alto Networks PAN-OS software where the connection details for a scheduled configuration export are logged in system logs. Logged information includes the cleartext username, passw...
CVE-2021-3031
- EPSS 0.09%
- Published 13.01.2021 18:15:14
- Last modified 21.11.2024 06:20:47
Padding bytes in Ethernet packets on PA-200, PA-220, PA-500, PA-800, PA-2000 Series, PA-3000 Series, PA-3200 Series, PA-5200 Series, and PA-7000 Series firewalls are not cleared before the data frame is created. This leaks a small amount of random in...
CVE-2021-3032
- EPSS 0.11%
- Published 13.01.2021 18:15:14
- Last modified 21.11.2024 06:20:47
An information exposure through log file vulnerability exists in Palo Alto Networks PAN-OS software where configuration secrets for the “http”, “email”, and “snmptrap” v3 log forwarding server profiles can be logged to the logrcvr.log system log. Log...
CVE-2020-1999
- EPSS 0.11%
- Published 12.11.2020 00:15:10
- Last modified 21.11.2024 05:11:49
A vulnerability exists in the Palo Alto Network PAN-OS signature-based threat detection engine that allows an attacker to communicate with devices in the network in a way that is not analyzed for threats by sending data through specifically crafted T...