CVE-2024-9474
- EPSS 94.77%
- Veröffentlicht 18.11.2024 16:15:29
- Zuletzt bearbeitet 04.08.2026 05:16:32
A privilege escalation vulnerability in Palo Alto Networks PAN-OS software allows a PAN-OS administrator with access to the management web interface to perform actions on the firewall with root privileges. Cloud NGFW and Prisma Access are not impact...
CVE-2024-0012
- EPSS 99.7%
- Veröffentlicht 18.11.2024 16:15:11
- Zuletzt bearbeitet 04.08.2026 05:16:29
An authentication bypass in Palo Alto Networks PAN-OS software enables an unauthenticated attacker with network access to the management web interface to gain PAN-OS administrator privileges to perform administrative actions, tamper with the configur...
CVE-2024-5919
- EPSS 0.35%
- Veröffentlicht 14.11.2024 10:15:09
- Zuletzt bearbeitet 24.01.2025 16:06:00
A blind XML External Entities (XXE) injection vulnerability in the Palo Alto Networks PAN-OS software enables an authenticated attacker to exfiltrate arbitrary files from firewalls to an attacker controlled server. This attack requires network access...
CVE-2024-5920
- EPSS 0.29%
- Veröffentlicht 14.11.2024 10:15:09
- Zuletzt bearbeitet 24.01.2025 16:06:43
A cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS software enables an authenticated read-write Panorama administrator to push a specially crafted configuration to a PAN-OS node. This enables impersonation of a legitimate PAN-OS ...
CVE-2024-9472
- EPSS 0.43%
- Veröffentlicht 14.11.2024 10:15:09
- Zuletzt bearbeitet 15.04.2026 00:35:42
A null pointer dereference in Palo Alto Networks PAN-OS software on PA-800 Series, PA-3200 Series, PA-5200 Series, and PA-7000 Series hardware platforms when Decryption policy is enabled allows an unauthenticated attacker to crash PAN-OS by sending s...
CVE-2024-5917
- EPSS 0.48%
- Veröffentlicht 14.11.2024 10:15:08
- Zuletzt bearbeitet 24.01.2025 16:04:54
A server-side request forgery in PAN-OS software enables an authenticated attacker with administrative privileges to use the administrative web interface as a proxy, which enables the attacker to view internal network resources not otherwise accessib...
CVE-2024-5918
- EPSS 0.17%
- Veröffentlicht 14.11.2024 10:15:08
- Zuletzt bearbeitet 01.10.2025 18:41:27
An improper certificate validation vulnerability in Palo Alto Networks PAN-OS software enables an authorized user with a specially crafted client certificate to connect to an impacted GlobalProtect portal or GlobalProtect gateway as a different legit...
CVE-2024-2550
- EPSS 0.51%
- Veröffentlicht 14.11.2024 10:15:04
- Zuletzt bearbeitet 24.01.2025 16:02:49
A null pointer dereference vulnerability in the GlobalProtect gateway in Palo Alto Networks PAN-OS software enables an unauthenticated attacker to stop the GlobalProtect service on the firewall by sending a specially crafted packet that causes a deni...
CVE-2024-2551
- EPSS 0.48%
- Veröffentlicht 14.11.2024 10:15:04
- Zuletzt bearbeitet 24.01.2025 16:03:41
A null pointer dereference vulnerability in Palo Alto Networks PAN-OS software enables an unauthenticated attacker to stop a core system service on the firewall by sending a crafted packet through the data plane that causes a denial of service (DoS) ...
- EPSS 0.47%
- Veröffentlicht 14.11.2024 10:15:04
- Zuletzt bearbeitet 24.01.2025 16:04:14
A command injection vulnerability in Palo Alto Networks PAN-OS software enables an authenticated administrator to bypass system restrictions in the management plane and delete files on the firewall.