- EPSS 0.6%
- Veröffentlicht 10.11.2021 17:15:10
- Zuletzt bearbeitet 21.11.2024 06:20:52
An OS command injection vulnerability in the Palo Alto Networks PAN-OS command line interface (CLI) enables an authenticated administrator with access to the CLI to execute arbitrary OS commands to escalate privileges. This issue impacts: PAN-OS 8.1 ...
CVE-2021-3062
- EPSS 0.36%
- Veröffentlicht 10.11.2021 17:15:10
- Zuletzt bearbeitet 21.11.2024 06:20:52
An improper access control vulnerability in PAN-OS software enables an attacker with authenticated access to GlobalProtect portals and gateways to connect to the EC2 instance metadata endpoint for VM-Series firewalls hosted on Amazon AWS. Exploitatio...
CVE-2021-3063
- EPSS 0.58%
- Veröffentlicht 10.11.2021 17:15:10
- Zuletzt bearbeitet 21.11.2024 06:20:53
An improper handling of exceptional conditions vulnerability exists in Palo Alto Networks GlobalProtect portal and gateway interfaces that enables an unauthenticated network-based attacker to send specifically crafted traffic to a GlobalProtect inter...
- EPSS 49.72%
- Veröffentlicht 10.11.2021 17:15:10
- Zuletzt bearbeitet 21.11.2024 06:20:53
A memory corruption vulnerability exists in Palo Alto Networks GlobalProtect portal and gateway interfaces that enables an unauthenticated network-based attacker to disrupt system processes and potentially execute arbitrary code with root privileges....
CVE-2021-3056
- EPSS 0.75%
- Veröffentlicht 10.11.2021 17:15:09
- Zuletzt bearbeitet 21.11.2024 06:20:51
A memory corruption vulnerability in Palo Alto Networks PAN-OS GlobalProtect Clientless VPN enables an authenticated attacker to execute arbitrary code with root user privileges during SAML authentication. This issue impacts: PAN-OS 8.1 versions earl...
- EPSS 1.04%
- Veröffentlicht 10.11.2021 17:15:09
- Zuletzt bearbeitet 21.11.2024 06:20:52
An OS command injection vulnerability in the Palo Alto Networks PAN-OS web interface enables an authenticated administrator with permissions to use XML API the ability to execute arbitrary OS commands to escalate privileges. This issue impacts: PAN-O...
CVE-2021-3052
- EPSS 0.63%
- Veröffentlicht 08.09.2021 17:15:12
- Zuletzt bearbeitet 21.11.2024 06:20:51
A reflected cross-site scripting (XSS) vulnerability in the Palo Alto Network PAN-OS web interface enables an authenticated network-based attacker to mislead another authenticated PAN-OS administrator to click on a specially crafted link that perform...
CVE-2021-3053
- EPSS 0.6%
- Veröffentlicht 08.09.2021 17:15:12
- Zuletzt bearbeitet 21.11.2024 06:20:51
An improper handling of exceptional conditions vulnerability exists in the Palo Alto Networks PAN-OS dataplane that enables an unauthenticated network-based attacker to send specifically crafted traffic through the firewall that causes the service to...
CVE-2021-3054
- EPSS 0.64%
- Veröffentlicht 08.09.2021 17:15:12
- Zuletzt bearbeitet 21.11.2024 06:20:51
A time-of-check to time-of-use (TOCTOU) race condition vulnerability in the Palo Alto Networks PAN-OS web interface enables an authenticated administrator with permission to upload plugins to execute arbitrary code with root user privileges. This iss...
CVE-2021-3055
- EPSS 0.28%
- Veröffentlicht 08.09.2021 17:15:12
- Zuletzt bearbeitet 21.11.2024 06:20:51
An improper restriction of XML external entity (XXE) reference vulnerability in the Palo Alto Networks PAN-OS web interface enables an authenticated administrator to read any arbitrary file from the file system and send a specifically crafted request...