Paloaltonetworks

Pan-os

229 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.66%
  • Veröffentlicht 16.08.2018 18:29:00
  • Zuletzt bearbeitet 21.11.2024 03:40:54

The PAN-OS Management Web Interface in Palo Alto Networks PAN-OS 8.1.2 and earlier may allow an authenticated user to shut down all management sessions, resulting in all logged in users to be redirected to the login page. PAN-OS 6.1, PAN-OS 7.1 and P...

  • EPSS 0.36%
  • Veröffentlicht 03.07.2018 21:29:01
  • Zuletzt bearbeitet 21.11.2024 04:15:21

The PAN-OS web interface administration page in PAN-OS 6.1.20 and earlier, PAN-OS 7.1.17 and earlier, PAN-OS 8.0.10 and earlier, and PAN-OS 8.1.1 and earlier may allow an attacker to inject arbitrary JavaScript or HTML.

  • EPSS 0.35%
  • Veröffentlicht 03.07.2018 21:29:00
  • Zuletzt bearbeitet 21.11.2024 04:12:26

The URL filtering "continue page" hosted by PAN-OS 8.0.10 and earlier may allow an attacker to inject arbitrary JavaScript or HTML via specially crafted URLs.

  • EPSS 0.1%
  • Veröffentlicht 03.07.2018 21:29:00
  • Zuletzt bearbeitet 21.11.2024 04:15:11

The PAN-OS management web interface page in PAN-OS 6.1.20 and earlier, PAN-OS 7.1.16 and earlier, PAN-OS 8.0.9 and earlier may allow an attacker to delete files in the system via specific request parameters.

  • EPSS 0.11%
  • Veröffentlicht 03.07.2018 21:29:00
  • Zuletzt bearbeitet 21.11.2024 04:15:21

The PAN-OS management web interface page in PAN-OS 6.1.20 and earlier, PAN-OS 7.1.16 and earlier, PAN-OS 8.0.8 and earlier, and PAN-OS 8.1.0 may allow an attacker to access the GlobalProtect password hashes of local users via manipulation of the HTML...

  • EPSS 0.36%
  • Veröffentlicht 03.07.2018 21:29:00
  • Zuletzt bearbeitet 21.11.2024 04:15:21

The PAN-OS session browser in PAN-OS 6.1.20 and earlier, PAN-OS 7.1.16 and earlier, PAN-OS 8.0.9 and earlier, and PAN-OS 8.1.1 and earlier may allow an attacker to inject arbitrary JavaScript or HTML.

  • EPSS 0.59%
  • Veröffentlicht 10.01.2018 18:29:01
  • Zuletzt bearbeitet 21.11.2024 03:15:29

Cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS before 6.1.19, 7.0.x before 7.0.19, 7.1.x before 7.1.14, and 8.0.x before 8.0.7, when the GlobalProtect gateway or portal is configured, allows remote attackers to inject arbitrary...

  • EPSS 0.24%
  • Veröffentlicht 10.01.2018 18:29:01
  • Zuletzt bearbeitet 21.11.2024 03:17:09

Cross-site scripting (XSS) vulnerability in the Captive Portal function in Palo Alto Networks PAN-OS before 8.0.7 allows remote attackers to inject arbitrary web script or HTML by leveraging an unspecified configuration.

  • EPSS 1.46%
  • Veröffentlicht 10.01.2018 18:29:01
  • Zuletzt bearbeitet 21.11.2024 03:18:47

Palo Alto Networks PAN-OS 6.1, 7.1, and 8.0.x before 8.0.7, when an interface implements SSL decryption with RSA enabled or hosts a GlobalProtect portal or gateway, might allow remote attackers to decrypt TLS ciphertext data by leveraging a Bleichenb...

  • EPSS 6.14%
  • Veröffentlicht 11.12.2017 17:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

The web interface packet capture management component in Palo Alto Networks PAN-OS before 6.1.19, 7.0.x before 7.0.19, 7.1.x before 7.1.14, and 8.0.x before 8.0.6 allows remote authenticated users to execute arbitrary code via unspecified vectors.