Vulnerabilities > Paloaltonetworks

DATE CVE VULNERABILITY TITLE RISK
2023-04-12 CVE-2023-0005 Cleartext Storage of Sensitive Information vulnerability in Paloaltonetworks Pan-Os
A vulnerability in Palo Alto Networks PAN-OS software enables an authenticated administrator to expose the plaintext values of secrets stored in the device configuration and encrypted API keys.
network
low complexity
paloaltonetworks CWE-312
4.9
2023-04-12 CVE-2023-0006 Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Paloaltonetworks Globalprotect
A local file deletion vulnerability in the Palo Alto Networks GlobalProtect app on Windows devices enables a user to delete system files from the endpoint with elevated privileges through a race condition.
local
high complexity
paloaltonetworks CWE-367
6.3
2023-02-08 CVE-2023-0001 Cleartext Transmission of Sensitive Information vulnerability in Paloaltonetworks Cortex XDR Agent 7.5/7.5.101
An information exposure vulnerability in the Palo Alto Networks Cortex XDR agent on Windows devices allows a local system administrator to disclose the admin password for the agent in cleartext, which bad actors can then use to execute privileged cytool commands that disable or uninstall the agent.
local
low complexity
paloaltonetworks CWE-319
6.7
2023-02-08 CVE-2023-0002 Unspecified vulnerability in Paloaltonetworks Cortex XDR Agent
A problem with a protection mechanism in the Palo Alto Networks Cortex XDR agent on Windows devices allows a local user to execute privileged cytool commands that disable or uninstall the agent.
local
low complexity
paloaltonetworks
7.8
2023-02-08 CVE-2023-0003 Externally Controlled Reference to a Resource in Another Sphere vulnerability in multiple products
A file disclosure vulnerability in the Palo Alto Networks Cortex XSOAR server software enables an authenticated user with access to the web interface to read local files from the server.
network
low complexity
paloaltonetworks fedoraproject CWE-610
6.5
2022-11-09 CVE-2022-0031 Insufficient Verification of Data Authenticity vulnerability in Paloaltonetworks Cortex Xsoar 6.5.0/6.6.0/6.8.0
A local privilege escalation (PE) vulnerability in the Palo Alto Networks Cortex XSOAR engine software running on a Linux operating system allows a local attacker with shell access to the engine to execute programs with elevated privileges.
local
low complexity
paloaltonetworks CWE-345
6.7
2022-10-12 CVE-2022-0030 Authentication Bypass by Spoofing vulnerability in Paloaltonetworks Pan-Os
An authentication bypass vulnerability in the Palo Alto Networks PAN-OS 8.1 web interface allows a network-based attacker with specific knowledge of the target firewall or Panorama appliance to impersonate an existing PAN-OS administrator and perform privileged actions.
network
high complexity
paloaltonetworks CWE-290
8.1
2022-09-14 CVE-2022-0029 Link Following vulnerability in Paloaltonetworks Cortex XDR Agent
An improper link resolution vulnerability in the Palo Alto Networks Cortex XDR agent on Windows devices allows a local attacker to read files on the system with elevated privileges when generating a tech support file.
local
low complexity
paloaltonetworks CWE-59
5.5
2022-08-10 CVE-2022-0028 Unspecified vulnerability in Paloaltonetworks Pan-Os
A PAN-OS URL filtering policy misconfiguration could allow a network-based attacker to conduct reflected and amplified TCP denial-of-service (RDoS) attacks.
network
low complexity
paloaltonetworks
8.6
2022-05-11 CVE-2022-0024 Unspecified vulnerability in Paloaltonetworks Pan-Os
A vulnerability exists in Palo Alto Networks PAN-OS software that enables an authenticated network-based PAN-OS administrator to upload a specifically created configuration that disrupts system processes and potentially execute arbitrary code with root privileges when the configuration is committed on both hardware and virtual firewalls.
network
low complexity
paloaltonetworks
7.2