Paloaltonetworks

Pan-os

229 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.33%
  • Veröffentlicht 08.09.2021 17:15:12
  • Zuletzt bearbeitet 21.11.2024 06:20:51

An improper handling of exceptional conditions vulnerability exists in the Palo Alto Networks PAN-OS dataplane that enables an unauthenticated network-based attacker to send specifically crafted traffic through the firewall that causes the service to...

  • EPSS 0.64%
  • Veröffentlicht 08.09.2021 17:15:12
  • Zuletzt bearbeitet 21.11.2024 06:20:51

A time-of-check to time-of-use (TOCTOU) race condition vulnerability in the Palo Alto Networks PAN-OS web interface enables an authenticated administrator with permission to upload plugins to execute arbitrary code with root user privileges. This iss...

  • EPSS 0.28%
  • Veröffentlicht 08.09.2021 17:15:12
  • Zuletzt bearbeitet 21.11.2024 06:20:51

An improper restriction of XML external entity (XXE) reference vulnerability in the Palo Alto Networks PAN-OS web interface enables an authenticated administrator to read any arbitrary file from the file system and send a specifically crafted request...

  • EPSS 0.6%
  • Veröffentlicht 11.08.2021 17:15:07
  • Zuletzt bearbeitet 21.11.2024 06:20:50

An OS command argument injection vulnerability in the Palo Alto Networks PAN-OS web interface enables an authenticated administrator to read any arbitrary file from the file system. This issue impacts: PAN-OS 8.1 versions earlier than PAN-OS 8.1.19; ...

  • EPSS 0.25%
  • Veröffentlicht 11.08.2021 17:15:07
  • Zuletzt bearbeitet 21.11.2024 06:20:50

An improper authentication vulnerability exists in Palo Alto Networks PAN-OS software that enables a SAML authenticated attacker to impersonate any other user in the GlobalProtect Portal and GlobalProtect Gateway when they are configured to use SAML ...

  • EPSS 0.28%
  • Veröffentlicht 11.08.2021 17:15:07
  • Zuletzt bearbeitet 21.11.2024 06:20:50

A cryptographically weak pseudo-random number generator (PRNG) is used during authentication to the Palo Alto Networks PAN-OS web interface. This enables an authenticated attacker, with the capability to observe their own authentication secrets over ...

  • EPSS 0.59%
  • Veröffentlicht 11.08.2021 17:15:07
  • Zuletzt bearbeitet 21.11.2024 06:20:50

Certain invalid URL entries contained in an External Dynamic List (EDL) cause the Device Server daemon (devsrvr) to stop responding. This condition causes subsequent commits on the firewall to fail and prevents administrators from performing commits ...

  • EPSS 3.48%
  • Veröffentlicht 11.08.2021 17:15:07
  • Zuletzt bearbeitet 21.11.2024 06:20:50

An OS command injection vulnerability in the Palo Alto Networks PAN-OS web interface enables an authenticated administrator to execute arbitrary OS commands to escalate privileges. This issue impacts: PAN-OS 9.0 version 9.0.10 through PAN-OS 9.0.14; ...

  • EPSS 0.14%
  • Veröffentlicht 20.04.2021 04:15:12
  • Zuletzt bearbeitet 21.11.2024 06:20:48

An information exposure through log file vulnerability exists in Palo Alto Networks PAN-OS software where secrets in PAN-OS XML API requests are logged in cleartext to the web server logs when the API is used incorrectly. This vulnerability applies o...

  • EPSS 0.07%
  • Veröffentlicht 20.04.2021 04:15:12
  • Zuletzt bearbeitet 21.11.2024 06:20:48

An information exposure through log file vulnerability exists in Palo Alto Networks PAN-OS software where the connection details for a scheduled configuration export are logged in system logs. Logged information includes the cleartext username, passw...