Vulnerabilities > Paloaltonetworks

DATE CVE VULNERABILITY TITLE RISK
2020-05-13 CVE-2020-1993 Session Fixation vulnerability in Paloaltonetworks Pan-Os
The GlobalProtect Portal feature in PAN-OS does not set a new session identifier after a successful user login, which allows session fixation attacks, if an attacker is able to control a user's session ID.
network
low complexity
paloaltonetworks CWE-384
5.4
2020-04-08 CVE-2020-1992 Use of Externally-Controlled Format String vulnerability in Paloaltonetworks Pan-Os
A format string vulnerability in the Varrcvr daemon of PAN-OS on PA-7000 Series devices with a Log Forwarding Card (LFC) allows remote attackers to crash the daemon creating a denial of service condition or potentially execute code with root privileges.
network
low complexity
paloaltonetworks CWE-134
critical
9.8
2020-04-08 CVE-2020-1991 Improper Privilege Management vulnerability in Paloaltonetworks Traps
An insecure temporary file vulnerability in Palo Alto Networks Traps allows a local authenticated Windows user to escalate privileges or overwrite system files.
local
low complexity
paloaltonetworks CWE-269
7.1
2020-04-08 CVE-2020-1990 Out-of-bounds Write vulnerability in Paloaltonetworks Pan-Os
A stack-based buffer overflow vulnerability in the management server component of PAN-OS allows an authenticated user to upload a corrupted PAN-OS configuration and potentially execute code with root privileges.
network
low complexity
paloaltonetworks CWE-787
7.2
2020-04-08 CVE-2020-1989 Improper Privilege Management vulnerability in Paloaltonetworks Globalprotect
An incorrect privilege assignment vulnerability when writing application-specific files in the Palo Alto Networks Global Protect Agent for Linux on ARM platform allows a local authenticated user to gain root privileges on the system.
local
low complexity
paloaltonetworks CWE-269
7.8
2020-04-08 CVE-2020-1988 Unquoted Search Path or Element vulnerability in Paloaltonetworks Globalprotect
An unquoted search path vulnerability in the Windows release of Global Protect Agent allows an authenticated local user with file creation privileges on the root of the OS disk (C:\) or to Program Files directory to gain system privileges.
local
low complexity
paloaltonetworks CWE-428
6.7
2020-04-08 CVE-2020-1987 Information Exposure Through Log Files vulnerability in Paloaltonetworks Globalprotect
An information exposure vulnerability in the logging component of Palo Alto Networks Global Protect Agent allows a local authenticated user to read VPN cookie information when the troubleshooting logging level is set to "Dump".
local
low complexity
paloaltonetworks CWE-532
3.3
2020-04-08 CVE-2020-1986 Improper Input Validation vulnerability in Paloaltonetworks Secdo
Improper input validation vulnerability in Secdo allows an authenticated local user with 'create folders or append data' access to the root of the OS disk (C:\) to cause a system crash on every login.
local
low complexity
paloaltonetworks CWE-20
5.5
2020-04-08 CVE-2020-1985 Incorrect Default Permissions vulnerability in Paloaltonetworks Secdo
Incorrect Default Permissions on C:\Programdata\Secdo\Logs folder in Secdo allows local authenticated users to overwrite system files and gain escalated privileges.
local
low complexity
paloaltonetworks CWE-276
7.8
2020-04-08 CVE-2020-1984 Improper Input Validation vulnerability in Paloaltonetworks Secdo
Secdo tries to execute a script at a hardcoded path if present, which allows a local authenticated user with 'create folders or append data' access to the root of the OS disk (C:\) to gain system privileges if the path does not already exist or is writable.
local
low complexity
paloaltonetworks CWE-20
7.8