CVE-2024-0010
- EPSS 3.05%
- Veröffentlicht 14.02.2024 18:15:47
- Zuletzt bearbeitet 09.12.2024 15:08:43
A reflected cross-site scripting (XSS) vulnerability in the GlobalProtect portal feature of Palo Alto Networks PAN-OS software enables execution of malicious JavaScript (in the context of a user’s browser) if a user clicks on a malicious link, allowi...
CVE-2024-0011
- EPSS 0.75%
- Veröffentlicht 14.02.2024 18:15:47
- Zuletzt bearbeitet 09.12.2024 15:05:57
A reflected cross-site scripting (XSS) vulnerability in the Captive Portal feature of Palo Alto Networks PAN-OS software enables execution of malicious JavaScript (in the context of an authenticated Captive Portal user’s browser) if a user clicks on ...
CVE-2023-6794
- EPSS 0.09%
- Veröffentlicht 13.12.2023 19:15:10
- Zuletzt bearbeitet 21.11.2024 08:44:34
An arbitrary file upload vulnerability in Palo Alto Networks PAN-OS software enables an authenticated read-write administrator with access to the web interface to disrupt system processes and potentially execute arbitrary code with limited privileges...
CVE-2023-6795
- EPSS 0.12%
- Veröffentlicht 13.12.2023 19:15:10
- Zuletzt bearbeitet 21.11.2024 08:44:34
An OS command injection vulnerability in Palo Alto Networks PAN-OS software enables an authenticated administrator to disrupt system processes and potentially execute arbitrary code with limited privileges on the firewall.
CVE-2023-6790
- EPSS 0.19%
- Veröffentlicht 13.12.2023 19:15:09
- Zuletzt bearbeitet 21.11.2024 08:44:33
A DOM-Based cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS software enables a remote attacker to execute a JavaScript payload in the context of an administrator’s browser when they view a specifically crafted link to the PAN-OS...
CVE-2023-6791
- EPSS 0.12%
- Veröffentlicht 13.12.2023 19:15:09
- Zuletzt bearbeitet 21.11.2024 08:44:34
A credential disclosure vulnerability in Palo Alto Networks PAN-OS software enables an authenticated read-only administrator to obtain the plaintext credentials of stored external system integrations such as LDAP, SCP, RADIUS, TACACS+, and SNMP from ...
CVE-2023-6792
- EPSS 0.2%
- Veröffentlicht 13.12.2023 19:15:09
- Zuletzt bearbeitet 21.11.2024 08:44:34
An OS command injection vulnerability in the XML API of Palo Alto Networks PAN-OS software enables an authenticated API user to disrupt system processes and potentially execute arbitrary code with limited privileges on the firewall.
CVE-2023-6793
- EPSS 0.08%
- Veröffentlicht 13.12.2023 19:15:09
- Zuletzt bearbeitet 21.11.2024 08:44:34
An improper privilege management vulnerability in Palo Alto Networks PAN-OS software enables an authenticated read-only administrator to revoke active XML API keys from the firewall and disrupt XML API usage.
CVE-2023-6789
- EPSS 0.16%
- Veröffentlicht 13.12.2023 19:15:08
- Zuletzt bearbeitet 21.11.2024 08:44:33
A cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS software enables a malicious authenticated read-write administrator to store a JavaScript payload using the web interface. Then, when viewed by a properly authenticated administr...
CVE-2023-38046
- EPSS 0.19%
- Veröffentlicht 12.07.2023 17:15:08
- Zuletzt bearbeitet 21.11.2024 08:12:44
A vulnerability exists in Palo Alto Networks PAN-OS software that enables an authenticated administrator with the privilege to commit a specifically created configuration to read local files and resources from the system.