CVE-2023-0010
- EPSS 0.66%
- Veröffentlicht 14.06.2023 17:15:09
- Zuletzt bearbeitet 21.11.2024 07:36:23
A reflected cross-site scripting (XSS) vulnerability in the Captive Portal feature of Palo Alto Networks PAN-OS software can allow a JavaScript payload to be executed in the context of an authenticated Captive Portal user’s browser when they click on...
CVE-2023-0008
- EPSS 0.27%
- Veröffentlicht 10.05.2023 17:15:09
- Zuletzt bearbeitet 21.11.2024 07:36:22
A file disclosure vulnerability in Palo Alto Networks PAN-OS software enables an authenticated read-write administrator with access to the web interface to export local files from the firewall through a race condition.
CVE-2023-0007
- EPSS 0.51%
- Veröffentlicht 10.05.2023 17:15:08
- Zuletzt bearbeitet 21.11.2024 07:36:22
A cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS software on Panorama appliances enables an authenticated read-write administrator to store a JavaScript payload in the web interface that will execute in the context of another a...
CVE-2023-0004
- EPSS 0.97%
- Veröffentlicht 12.04.2023 17:15:07
- Zuletzt bearbeitet 21.11.2024 07:36:22
A local file deletion vulnerability in Palo Alto Networks PAN-OS software enables an authenticated administrator to delete files from the local file system with elevated privileges. These files can include logs and system components that impact the ...
CVE-2023-0005
- EPSS 0.25%
- Veröffentlicht 12.04.2023 17:15:07
- Zuletzt bearbeitet 21.11.2024 07:36:22
A vulnerability in Palo Alto Networks PAN-OS software enables an authenticated administrator to expose the plaintext values of secrets stored in the device configuration and encrypted API keys.
CVE-2022-0030
- EPSS 0.09%
- Veröffentlicht 12.10.2022 17:15:10
- Zuletzt bearbeitet 21.11.2024 06:37:51
An authentication bypass vulnerability in the Palo Alto Networks PAN-OS 8.1 web interface allows a network-based attacker with specific knowledge of the target firewall or Panorama appliance to impersonate an existing PAN-OS administrator and perform...
CVE-2022-0028
- EPSS 3.62%
- Veröffentlicht 10.08.2022 16:15:08
- Zuletzt bearbeitet 04.11.2025 16:49:41
A PAN-OS URL filtering policy misconfiguration could allow a network-based attacker to conduct reflected and amplified TCP denial-of-service (RDoS) attacks. The DoS attack would appear to originate from a Palo Alto Networks PA-Series (hardware), VM-S...
- EPSS 1.37%
- Veröffentlicht 11.05.2022 17:15:09
- Zuletzt bearbeitet 21.11.2024 06:37:50
A vulnerability exists in Palo Alto Networks PAN-OS software that enables an authenticated network-based PAN-OS administrator to upload a specifically created configuration that disrupts system processes and potentially execute arbitrary code with ro...
CVE-2022-0023
- EPSS 0.78%
- Veröffentlicht 13.04.2022 19:15:09
- Zuletzt bearbeitet 21.11.2024 06:37:50
An improper handling of exceptional conditions vulnerability exists in the DNS proxy feature of Palo Alto Networks PAN-OS software that enables a meddler-in-the-middle (MITM) to send specifically crafted traffic to the firewall that causes the servic...
CVE-2022-0022
- EPSS 0.07%
- Veröffentlicht 09.03.2022 18:15:07
- Zuletzt bearbeitet 21.11.2024 06:37:50
Usage of a weak cryptographic algorithm in Palo Alto Networks PAN-OS software where the password hashes of administrator and local user accounts are not created with a sufficient level of computational effort, which allows for password cracking attac...