CVE-2024-8688
- EPSS 0.02%
- Published 11.09.2024 17:15:14
- Last modified 03.10.2024 00:19:32
An improper neutralization of matching symbols vulnerability in the Palo Alto Networks PAN-OS command line interface (CLI) enables authenticated administrators (including read-only administrators) with access to the CLI to to read arbitrary files on ...
CVE-2024-8691
- EPSS 0.44%
- Published 11.09.2024 17:15:14
- Last modified 01.11.2024 14:26:46
A vulnerability in the GlobalProtect portal in Palo Alto Networks PAN-OS software enables a malicious authenticated GlobalProtect user to impersonate another GlobalProtect user. Active GlobalProtect users impersonated by an attacker who is exploiting...
CVE-2024-5916
- EPSS 0.07%
- Published 14.08.2024 17:15:18
- Last modified 20.08.2024 19:30:11
An information exposure vulnerability in Palo Alto Networks PAN-OS software enables a local system administrator to unintentionally disclose secrets, passwords, and tokens of external systems. A read-only administrator who has access to the config lo...
- EPSS 0.16%
- Published 10.07.2024 19:15:11
- Last modified 21.11.2024 09:48:34
An arbitrary file upload vulnerability in Palo Alto Networks Panorama software enables an authenticated read-write administrator with access to the web interface to disrupt system processes and crash the Panorama. Repeated attacks eventually cause th...
CVE-2024-5913
- EPSS 0.09%
- Published 10.07.2024 19:15:11
- Last modified 24.01.2025 16:00:42
An improper input validation vulnerability in Palo Alto Networks PAN-OS software enables an attacker with the ability to tamper with the physical file system to elevate privileges.
- EPSS 94.3%
- Published 12.04.2024 08:15:06
- Last modified 29.11.2024 16:47:54
A command injection as a result of arbitrary file creation vulnerability in the GlobalProtect feature of Palo Alto Networks PAN-OS software for specific PAN-OS versions and distinct feature configurations may enable an unauthenticated attacker to exe...
CVE-2024-3383
- EPSS 0.25%
- Published 10.04.2024 17:15:57
- Last modified 24.01.2025 15:29:26
A vulnerability in how Palo Alto Networks PAN-OS software processes data received from Cloud Identity Engine (CIE) agents enables modification of User-ID groups. This impacts user access to network resources where users may be inappropriately denied ...
CVE-2024-3384
- EPSS 0.73%
- Published 10.04.2024 17:15:57
- Last modified 24.01.2025 15:54:56
A vulnerability in Palo Alto Networks PAN-OS software enables a remote attacker to reboot PAN-OS firewalls when receiving Windows New Technology LAN Manager (NTLM) packets from Windows servers. Repeated attacks eventually cause the firewall to enter ...
CVE-2024-3385
- EPSS 2.12%
- Published 10.04.2024 17:15:57
- Last modified 24.01.2025 15:55:48
A packet processing mechanism in Palo Alto Networks PAN-OS software enables a remote attacker to reboot hardware-based firewalls. Repeated attacks eventually cause the firewall to enter maintenance mode, which requires manual intervention to bring th...
CVE-2024-3386
- EPSS 0.24%
- Published 10.04.2024 17:15:57
- Last modified 24.01.2025 15:58:52
An incorrect string comparison vulnerability in Palo Alto Networks PAN-OS software prevents Predefined Decryption Exclusions from functioning as intended. This can cause traffic destined for domains that are not specified in Predefined Decryption Exc...