Paloaltonetworks

Pan-os

226 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.02%
  • Veröffentlicht 10.04.2024 17:15:57
  • Zuletzt bearbeitet 21.11.2024 09:29:30

A weak (low bit strength) device certificate in Palo Alto Networks Panorama software enables an attacker to perform a meddler-in-the-middle (MitM) attack to capture encrypted traffic between the Panorama management server and the firewalls it manages...

  • EPSS 0.18%
  • Veröffentlicht 10.04.2024 17:15:57
  • Zuletzt bearbeitet 24.01.2025 16:16:18

A vulnerability in the GlobalProtect Gateway in Palo Alto Networks PAN-OS software enables an authenticated attacker to impersonate another user and send network packets to internal assets. However, this vulnerability does not allow the attacker to r...

  • EPSS 0.37%
  • Veröffentlicht 10.04.2024 17:15:56
  • Zuletzt bearbeitet 22.01.2025 15:44:24

A memory leak exists in Palo Alto Networks PAN-OS software that enables an attacker to send a burst of crafted packets through the firewall that eventually prevents the firewall from processing traffic. This issue applies only to PA-5400 Series devic...

  • EPSS 0.04%
  • Veröffentlicht 13.03.2024 18:15:08
  • Zuletzt bearbeitet 21.11.2024 09:09:44

An improper authorization vulnerability in Palo Alto Networks Panorama software enables an authenticated read-only administrator to upload files using the web interface and completely fill one of the disk partitions with those uploaded files, which p...

  • EPSS 0.53%
  • Veröffentlicht 14.02.2024 18:15:47
  • Zuletzt bearbeitet 17.12.2024 18:09:56

A cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS software enables a malicious authenticated read-write administrator to store a JavaScript payload using the web interface on Panorama appliances. This enables the impersonation o...

  • EPSS 0.25%
  • Veröffentlicht 14.02.2024 18:15:47
  • Zuletzt bearbeitet 09.12.2024 15:18:26

Web sessions in the management interface in Palo Alto Networks PAN-OS software do not expire in certain situations, making it susceptible to unauthorized access.

  • EPSS 0.1%
  • Veröffentlicht 14.02.2024 18:15:47
  • Zuletzt bearbeitet 09.12.2024 15:13:34

An improper verification vulnerability in the GlobalProtect gateway feature of Palo Alto Networks PAN-OS software enables a malicious user with stolen credentials to establish a VPN connection from an unauthorized IP address.

  • EPSS 2.43%
  • Veröffentlicht 14.02.2024 18:15:47
  • Zuletzt bearbeitet 09.12.2024 15:08:43

A reflected cross-site scripting (XSS) vulnerability in the GlobalProtect portal feature of Palo Alto Networks PAN-OS software enables execution of malicious JavaScript (in the context of a user’s browser) if a user clicks on a malicious link, allowi...

  • EPSS 0.75%
  • Veröffentlicht 14.02.2024 18:15:47
  • Zuletzt bearbeitet 09.12.2024 15:05:57

A reflected cross-site scripting (XSS) vulnerability in the Captive Portal feature of Palo Alto Networks PAN-OS software enables execution of malicious JavaScript (in the context of an authenticated Captive Portal user’s browser) if a user clicks on ...

  • EPSS 0.09%
  • Veröffentlicht 13.12.2023 19:15:10
  • Zuletzt bearbeitet 21.11.2024 08:44:34

An arbitrary file upload vulnerability in Palo Alto Networks PAN-OS software enables an authenticated read-write administrator with access to the web interface to disrupt system processes and potentially execute arbitrary code with limited privileges...