CVE-2025-0116
- EPSS 0.16%
- Veröffentlicht 12.03.2025 18:34:38
- Zuletzt bearbeitet 18.03.2025 00:15:12
A Denial of Service (DoS) vulnerability in Palo Alto Networks PAN-OS software causes the firewall to unexpectedly reboot when processing a specially crafted LLDP frame sent by an unauthenticated adjacent attacker. Repeated attempts to initiate this c...
CVE-2025-0115
- EPSS 0.11%
- Veröffentlicht 12.03.2025 18:30:13
- Zuletzt bearbeitet 15.03.2025 00:15:11
A vulnerability in the Palo Alto Networks PAN-OS software enables an authenticated admin on the PAN-OS CLI to read arbitrary files. The attacker must have network access to the management interface (web, SSH, console, or telnet) and successfully aut...
CVE-2025-0114
- EPSS 0.11%
- Veröffentlicht 12.03.2025 18:20:05
- Zuletzt bearbeitet 22.10.2025 19:23:43
A Denial of Service (DoS) vulnerability in the GlobalProtect feature of Palo Alto Networks PAN-OS software enables an unauthenticated attacker to render the service unavailable by sending a large number of specially crafted packets over a period of t...
CVE-2025-0108
- EPSS 94.06%
- Veröffentlicht 12.02.2025 21:15:16
- Zuletzt bearbeitet 04.11.2025 16:49:25
An authentication bypass in the Palo Alto Networks PAN-OS software enables an unauthenticated attacker with network access to the management web interface to bypass the authentication otherwise required by the PAN-OS management web interface and invo...
CVE-2025-0109
- EPSS 1.22%
- Veröffentlicht 12.02.2025 21:15:16
- Zuletzt bearbeitet 12.02.2025 21:15:16
An unauthenticated file deletion vulnerability in the Palo Alto Networks PAN-OS management web interface enables an unauthenticated attacker with network access to the management web interface to delete certain files as the “nobody” user; this includ...
CVE-2025-0111
- EPSS 2.94%
- Veröffentlicht 12.02.2025 21:15:16
- Zuletzt bearbeitet 04.11.2025 16:49:34
An authenticated file read vulnerability in the Palo Alto Networks PAN-OS software enables an authenticated attacker with network access to the management web interface to read files on the PAN-OS filesystem that are readable by the “nobody” user. Y...
CVE-2025-0103
- EPSS 0.59%
- Veröffentlicht 11.01.2025 03:15:22
- Zuletzt bearbeitet 23.01.2026 22:03:57
An SQL injection vulnerability in Palo Alto Networks Expedition enables an authenticated attacker to reveal Expedition database contents, such as password hashes, usernames, device configurations, and device API keys. This vulnerability also enables ...
CVE-2025-0104
- EPSS 0.77%
- Veröffentlicht 11.01.2025 03:15:22
- Zuletzt bearbeitet 23.01.2026 22:03:41
A reflected cross-site scripting (XSS) vulnerability in Palo Alto Networks Expedition enables attackers to execute malicious JavaScript code in the context of an authenticated Expedition user’s browser if that authenticated user clicks a malicious li...
CVE-2025-0105
- EPSS 4.37%
- Veröffentlicht 11.01.2025 03:15:22
- Zuletzt bearbeitet 23.01.2026 21:56:51
An arbitrary file deletion vulnerability in Palo Alto Networks Expedition enables an unauthenticated attacker to delete arbitrary files accessible to the www-data user on the host filesystem.
CVE-2025-0106
- EPSS 0.51%
- Veröffentlicht 11.01.2025 03:15:22
- Zuletzt bearbeitet 23.01.2026 21:52:57
A wildcard expansion vulnerability in Palo Alto Networks Expedition allows an unauthenticated attacker to enumerate files on the host filesystem.