Vulnerabilities > Paloaltonetworks > PAN OS > 10.0.3

DATE CVE VULNERABILITY TITLE RISK
2022-03-09 CVE-2022-0022 Use of Password Hash With Insufficient Computational Effort vulnerability in Paloaltonetworks Pan-Os
Usage of a weak cryptographic algorithm in Palo Alto Networks PAN-OS software where the password hashes of administrator and local user accounts are not created with a sufficient level of computational effort, which allows for password cracking attacks on accounts in normal (non-FIPS-CC) operational mode.
local
low complexity
paloaltonetworks CWE-916
4.4
2022-02-10 CVE-2022-0011 Interpretation Conflict vulnerability in Paloaltonetworks Pan-Os
PAN-OS software provides options to exclude specific websites from URL category enforcement and those websites are blocked or allowed (depending on your rules) regardless of their associated URL category.
network
low complexity
paloaltonetworks CWE-436
6.5
2021-11-10 CVE-2021-3058 OS Command Injection vulnerability in Paloaltonetworks Pan-Os
An OS command injection vulnerability in the Palo Alto Networks PAN-OS web interface enables an authenticated administrator with permissions to use XML API the ability to execute arbitrary OS commands to escalate privileges.
network
low complexity
paloaltonetworks CWE-78
7.2
2021-11-10 CVE-2021-3059 OS Command Injection vulnerability in Paloaltonetworks Pan-Os
An OS command injection vulnerability in the Palo Alto Networks PAN-OS management interface exists when performing dynamic updates.
network
high complexity
paloaltonetworks CWE-78
8.1
2021-11-10 CVE-2021-3060 OS Command Injection vulnerability in Paloaltonetworks Pan-Os
An OS command injection vulnerability in the Simple Certificate Enrollment Protocol (SCEP) feature of PAN-OS software allows an unauthenticated network-based attacker with specific knowledge of the firewall configuration to execute arbitrary code with root user privileges.
network
high complexity
paloaltonetworks CWE-78
8.1
2021-11-10 CVE-2021-3061 OS Command Injection vulnerability in Paloaltonetworks Pan-Os
An OS command injection vulnerability in the Palo Alto Networks PAN-OS command line interface (CLI) enables an authenticated administrator with access to the CLI to execute arbitrary OS commands to escalate privileges.
network
low complexity
paloaltonetworks CWE-78
7.2
2021-11-10 CVE-2021-3062 Unspecified vulnerability in Paloaltonetworks Pan-Os
An improper access control vulnerability in PAN-OS software enables an attacker with authenticated access to GlobalProtect portals and gateways to connect to the EC2 instance metadata endpoint for VM-Series firewalls hosted on Amazon AWS.
network
low complexity
paloaltonetworks
8.8
2021-11-10 CVE-2021-3063 Improper Handling of Exceptional Conditions vulnerability in Paloaltonetworks Pan-Os
An improper handling of exceptional conditions vulnerability exists in Palo Alto Networks GlobalProtect portal and gateway interfaces that enables an unauthenticated network-based attacker to send specifically crafted traffic to a GlobalProtect interface that causes the service to stop responding.
network
low complexity
paloaltonetworks CWE-755
7.5
2021-09-08 CVE-2021-3053 Improper Handling of Exceptional Conditions vulnerability in Paloaltonetworks Pan-Os
An improper handling of exceptional conditions vulnerability exists in the Palo Alto Networks PAN-OS dataplane that enables an unauthenticated network-based attacker to send specifically crafted traffic through the firewall that causes the service to crash.
network
low complexity
paloaltonetworks CWE-755
7.5
2021-09-08 CVE-2021-3054 Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Paloaltonetworks Pan-Os
A time-of-check to time-of-use (TOCTOU) race condition vulnerability in the Palo Alto Networks PAN-OS web interface enables an authenticated administrator with permission to upload plugins to execute arbitrary code with root user privileges.
network
high complexity
paloaltonetworks CWE-367
6.6