Vulnerabilities > Paloaltonetworks > PAN OS > 10.1.10

DATE CVE VULNERABILITY TITLE RISK
2024-04-10 CVE-2024-3388 Incorrect Authorization vulnerability in Paloaltonetworks Pan-Os
A vulnerability in the GlobalProtect Gateway in Palo Alto Networks PAN-OS software enables an authenticated attacker to impersonate another user and send network packets to internal assets.
network
low complexity
paloaltonetworks CWE-863
5.0
2024-02-14 CVE-2024-0008 Insufficient Session Expiration vulnerability in Paloaltonetworks Pan-Os
Web sessions in the management interface in Palo Alto Networks PAN-OS software do not expire in certain situations, making it susceptible to unauthorized access.
network
low complexity
paloaltonetworks CWE-613
8.8
2024-02-14 CVE-2024-0010 Cross-site Scripting vulnerability in Paloaltonetworks Pan-Os
A reflected cross-site scripting (XSS) vulnerability in the GlobalProtect portal feature of Palo Alto Networks PAN-OS software enables execution of malicious JavaScript (in the context of a user’s browser) if a user clicks on a malicious link, allowing phishing attacks that could lead to credential theft.
network
low complexity
paloaltonetworks CWE-79
6.1
2023-12-13 CVE-2023-6789 Cross-site Scripting vulnerability in Paloaltonetworks Pan-Os
A cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS software enables a malicious authenticated read-write administrator to store a JavaScript payload using the web interface.
network
low complexity
paloaltonetworks CWE-79
4.8
2023-12-13 CVE-2023-6793 Improper Privilege Management vulnerability in Paloaltonetworks Pan-Os
An improper privilege management vulnerability in Palo Alto Networks PAN-OS software enables an authenticated read-only administrator to revoke active XML API keys from the firewall and disrupt XML API usage.
network
low complexity
paloaltonetworks CWE-269
2.7