- EPSS 0.52%
- Published 10.06.2020 18:15:11
- Last modified 21.11.2024 05:24:29
An OS Command Injection vulnerability in PAN-OS management server allows authenticated administrators to execute arbitrary OS commands with root privileges when uploading a new certificate in FIPS-CC mode. This issue affects: All versions of PAN-OS 7...
- EPSS 1.11%
- Published 10.06.2020 18:15:11
- Last modified 21.11.2024 05:24:29
An OS Command Injection vulnerability in the PAN-OS web management interface allows authenticated administrators to execute arbitrary OS commands with root privileges by sending a malicious request to generate new certificates for use in the PAN-OS c...
CVE-2020-2013
- EPSS 0.34%
- Published 13.05.2020 19:15:14
- Last modified 21.11.2024 05:24:27
A cleartext transmission of sensitive information vulnerability in Palo Alto Networks PAN-OS Panorama that discloses an authenticated PAN-OS administrator's PAN-OS session cookie. When an administrator issues a context switch request into a managed f...
- EPSS 4.82%
- Published 13.05.2020 19:15:14
- Last modified 21.11.2024 05:24:27
An OS Command Injection vulnerability in PAN-OS management server allows authenticated users to inject and execute arbitrary shell commands with root privileges. This issue affects: All versions of PAN-OS 7.1 and 8.0; PAN-OS 8.1 versions earlier than...
- EPSS 1.74%
- Published 13.05.2020 19:15:14
- Last modified 21.11.2024 05:24:27
A buffer overflow vulnerability in the PAN-OS management server allows authenticated users to crash system processes or potentially execute arbitrary code with root privileges. This issue affects: PAN-OS 7.1 versions earlier than 7.1.26; PAN-OS 8.1 v...
CVE-2020-2016
- EPSS 0.21%
- Published 13.05.2020 19:15:14
- Last modified 21.11.2024 05:24:27
A race condition due to insecure creation of a file in a temporary directory vulnerability in PAN-OS allows for root privilege escalation from a limited linux user account. This allows an attacker who has escaped the restricted shell as a low privile...
CVE-2020-2017
- EPSS 0.49%
- Published 13.05.2020 19:15:14
- Last modified 21.11.2024 05:24:27
A DOM-Based Cross Site Scripting Vulnerability exists in PAN-OS and Panorama Management Web Interfaces. A remote attacker able to convince an authenticated administrator to click on a crafted link to PAN-OS and Panorama Web Interfaces could execute a...
CVE-2020-2018
- EPSS 0.16%
- Published 13.05.2020 19:15:14
- Last modified 21.11.2024 05:24:27
An authentication bypass vulnerability in the Panorama context switching feature allows an attacker with network access to a Panorama's management interface to gain privileged access to managed firewalls. An attacker requires some knowledge of manage...
CVE-2020-2003
- EPSS 0.33%
- Published 13.05.2020 19:15:13
- Last modified 21.11.2024 05:24:25
An external control of filename vulnerability in the command processing of PAN-OS allows an authenticated administrator to delete arbitrary system files affecting the integrity of the system or causing denial of service to all PAN-OS services. This i...
CVE-2020-2005
- EPSS 0.5%
- Published 13.05.2020 19:15:13
- Last modified 21.11.2024 05:24:25
A cross-site scripting (XSS) vulnerability exists when visiting malicious websites with the Palo Alto Networks GlobalProtect Clientless VPN that can compromise the user's active session. This issue affects: PAN-OS 7.1 versions earlier than 7.1.26; PA...