- EPSS 1.78%
- Veröffentlicht 09.09.2020 17:15:26
- Zuletzt bearbeitet 21.11.2024 05:24:32
A buffer overflow vulnerability in the PAN-OS management web interface allows authenticated administrators to disrupt system processes and potentially execute arbitrary code with root privileges. This issue impacts only PAN-OS 10.0 versions earlier t...
- EPSS 0.23%
- Veröffentlicht 09.09.2020 17:15:26
- Zuletzt bearbeitet 21.11.2024 05:24:32
An information exposure through log file vulnerability where sensitive fields are recorded in the configuration log without masking on Palo Alto Networks PAN-OS software when the after-change-detail custom syslog field is enabled for configuration lo...
- EPSS 0.23%
- Veröffentlicht 09.09.2020 17:15:26
- Zuletzt bearbeitet 21.11.2024 05:24:32
An information exposure through log file vulnerability where an administrator's password or other sensitive information may be logged in cleartext while using the CLI in Palo Alto Networks PAN-OS software. The opcmdhistory.log file was introduced to ...
CVE-2020-2036
- EPSS 81.95%
- Veröffentlicht 09.09.2020 17:15:25
- Zuletzt bearbeitet 21.11.2024 05:24:30
A reflected cross-site scripting (XSS) vulnerability exists in the PAN-OS management web interface. A remote attacker able to convince an administrator with an active authenticated session on the firewall management interface to click on a crafted li...
- EPSS 0.99%
- Veröffentlicht 09.09.2020 17:15:25
- Zuletzt bearbeitet 21.11.2024 05:24:31
An OS Command Injection vulnerability in the PAN-OS management interface that allows authenticated administrators to execute arbitrary OS commands with root privileges. This issue impacts: PAN-OS 8.1 versions earlier than PAN-OS 8.1.16; PAN-OS 9.0 ve...
- EPSS 88.02%
- Veröffentlicht 09.09.2020 17:15:25
- Zuletzt bearbeitet 21.11.2024 05:24:31
An OS Command Injection vulnerability in the PAN-OS management interface that allows authenticated administrators to execute arbitrary OS commands with root privileges. This issue impacts: PAN-OS 9.0 versions earlier than 9.0.10; PAN-OS 9.1 versions ...
CVE-2020-2039
- EPSS 11.15%
- Veröffentlicht 09.09.2020 17:15:25
- Zuletzt bearbeitet 21.11.2024 05:24:31
An uncontrolled resource consumption vulnerability in Palo Alto Networks PAN-OS allows for a remote unauthenticated user to upload temporary files through the management web interface that are not properly deleted after the request is finished. It is...
- EPSS 3.99%
- Veröffentlicht 09.09.2020 17:15:25
- Zuletzt bearbeitet 21.11.2024 05:24:31
A buffer overflow vulnerability in PAN-OS allows an unauthenticated attacker to disrupt system processes and potentially execute arbitrary code with root privileges by sending a malicious request to the Captive Portal or Multi-Factor Authentication i...
CVE-2020-2041
- EPSS 1.34%
- Veröffentlicht 09.09.2020 17:15:25
- Zuletzt bearbeitet 21.11.2024 05:24:31
An insecure configuration of the appweb daemon of Palo Alto Networks PAN-OS 8.1 allows a remote unauthenticated user to send a specifically crafted request to the device that causes the appweb service to crash. Repeated attempts to send this request ...
CVE-2020-2035
- EPSS 0.26%
- Veröffentlicht 12.08.2020 17:15:12
- Zuletzt bearbeitet 21.11.2024 05:24:30
When SSL/TLS Forward Proxy Decryption mode has been configured to decrypt the web transactions, the PAN-OS URL filtering feature inspects the HTTP Host and URL path headers for policy enforcement on the decrypted HTTPS web transactions but does not c...