Vulnerabilities > Paloaltonetworks > PAN OS > 10.0.3

DATE CVE VULNERABILITY TITLE RISK
2024-09-11 CVE-2024-8687 Unspecified vulnerability in Paloaltonetworks Pan-Os
An information exposure vulnerability exists in Palo Alto Networks PAN-OS software that enables a GlobalProtect end user to learn both the configured GlobalProtect uninstall password and the configured disable or disconnect passcode.
network
low complexity
paloaltonetworks
7.1
2024-09-11 CVE-2024-8688 Unspecified vulnerability in Paloaltonetworks Pan-Os
An improper neutralization of matching symbols vulnerability in the Palo Alto Networks PAN-OS command line interface (CLI) enables authenticated administrators (including read-only administrators) with access to the CLI to to read arbitrary files on the firewall.
local
low complexity
paloaltonetworks
4.4
2024-04-10 CVE-2024-3384 Unspecified vulnerability in Paloaltonetworks Pan-Os
A vulnerability in Palo Alto Networks PAN-OS software enables a remote attacker to reboot PAN-OS firewalls when receiving Windows New Technology LAN Manager (NTLM) packets from Windows servers.
network
low complexity
paloaltonetworks
7.5
2024-04-10 CVE-2024-3386 Interpretation Conflict vulnerability in Paloaltonetworks Pan-Os
An incorrect string comparison vulnerability in Palo Alto Networks PAN-OS software prevents Predefined Decryption Exclusions from functioning as intended.
network
low complexity
paloaltonetworks CWE-436
5.3
2024-02-14 CVE-2024-0007 Cross-site Scripting vulnerability in Paloaltonetworks Pan-Os
A cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS software enables a malicious authenticated read-write administrator to store a JavaScript payload using the web interface on Panorama appliances.
network
low complexity
paloaltonetworks CWE-79
4.8
2024-02-14 CVE-2024-0008 Insufficient Session Expiration vulnerability in Paloaltonetworks Pan-Os
Web sessions in the management interface in Palo Alto Networks PAN-OS software do not expire in certain situations, making it susceptible to unauthorized access.
network
low complexity
paloaltonetworks CWE-613
8.8
2024-02-14 CVE-2024-0011 Cross-site Scripting vulnerability in Paloaltonetworks Pan-Os
A reflected cross-site scripting (XSS) vulnerability in the Captive Portal feature of Palo Alto Networks PAN-OS software enables execution of malicious JavaScript (in the context of an authenticated Captive Portal user’s browser) if a user clicks on a malicious link, allowing phishing attacks that could lead to credential theft.
network
low complexity
paloaltonetworks CWE-79
6.1
2023-12-13 CVE-2023-6790 Cross-site Scripting vulnerability in Paloaltonetworks Pan-Os
A DOM-Based cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS software enables a remote attacker to execute a JavaScript payload in the context of an administrator’s browser when they view a specifically crafted link to the PAN-OS web interface.
network
low complexity
paloaltonetworks CWE-79
6.1
2023-12-13 CVE-2023-6791 Insufficiently Protected Credentials vulnerability in Paloaltonetworks Pan-Os
A credential disclosure vulnerability in Palo Alto Networks PAN-OS software enables an authenticated read-only administrator to obtain the plaintext credentials of stored external system integrations such as LDAP, SCP, RADIUS, TACACS+, and SNMP from the web interface.
network
low complexity
paloaltonetworks CWE-522
4.9
2023-12-13 CVE-2023-6792 OS Command Injection vulnerability in Paloaltonetworks Pan-Os
An OS command injection vulnerability in the XML API of Palo Alto Networks PAN-OS software enables an authenticated API user to disrupt system processes and potentially execute arbitrary code with limited privileges on the firewall.
network
low complexity
paloaltonetworks CWE-78
6.3