Vulnerabilities > Paloaltonetworks > PAN OS > 10.2.1

DATE CVE VULNERABILITY TITLE RISK
2024-02-14 CVE-2024-0008 Insufficient Session Expiration vulnerability in Paloaltonetworks Pan-Os
Web sessions in the management interface in Palo Alto Networks PAN-OS software do not expire in certain situations, making it susceptible to unauthorized access.
network
low complexity
paloaltonetworks CWE-613
8.8
2024-02-14 CVE-2024-0009 Origin Validation Error vulnerability in Paloaltonetworks Pan-Os
An improper verification vulnerability in the GlobalProtect gateway feature of Palo Alto Networks PAN-OS software enables a malicious user with stolen credentials to establish a VPN connection from an unauthorized IP address.
network
low complexity
paloaltonetworks CWE-346
6.3
2023-12-13 CVE-2023-6789 Cross-site Scripting vulnerability in Paloaltonetworks Pan-Os
A cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS software enables a malicious authenticated read-write administrator to store a JavaScript payload using the web interface.
network
low complexity
paloaltonetworks CWE-79
4.8
2023-12-13 CVE-2023-6790 Cross-site Scripting vulnerability in Paloaltonetworks Pan-Os
A DOM-Based cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS software enables a remote attacker to execute a JavaScript payload in the context of an administrator’s browser when they view a specifically crafted link to the PAN-OS web interface.
network
low complexity
paloaltonetworks CWE-79
6.1
2023-12-13 CVE-2023-6791 Insufficiently Protected Credentials vulnerability in Paloaltonetworks Pan-Os
A credential disclosure vulnerability in Palo Alto Networks PAN-OS software enables an authenticated read-only administrator to obtain the plaintext credentials of stored external system integrations such as LDAP, SCP, RADIUS, TACACS+, and SNMP from the web interface.
network
low complexity
paloaltonetworks CWE-522
4.9
2023-12-13 CVE-2023-6793 Improper Privilege Management vulnerability in Paloaltonetworks Pan-Os
An improper privilege management vulnerability in Palo Alto Networks PAN-OS software enables an authenticated read-only administrator to revoke active XML API keys from the firewall and disrupt XML API usage.
network
low complexity
paloaltonetworks CWE-269
2.7
2023-07-12 CVE-2023-38046 Externally Controlled Reference to a Resource in Another Sphere vulnerability in Paloaltonetworks Pan-Os
A vulnerability exists in Palo Alto Networks PAN-OS software that enables an authenticated administrator with the privilege to commit a specifically created configuration to read local files and resources from the system.
network
low complexity
paloaltonetworks CWE-610
4.9
2023-06-14 CVE-2023-0010 Cross-site Scripting vulnerability in Paloaltonetworks Pan-Os
A reflected cross-site scripting (XSS) vulnerability in the Captive Portal feature of Palo Alto Networks PAN-OS software can allow a JavaScript payload to be executed in the context of an authenticated Captive Portal user’s browser when they click on a specifically crafted link.
network
low complexity
paloaltonetworks CWE-79
5.4
2023-05-10 CVE-2023-0008 Externally Controlled Reference to a Resource in Another Sphere vulnerability in Paloaltonetworks Pan-Os
A file disclosure vulnerability in Palo Alto Networks PAN-OS software enables an authenticated read-write administrator with access to the web interface to export local files from the firewall through a race condition.
network
high complexity
paloaltonetworks CWE-610
4.4
2023-04-12 CVE-2023-0005 Cleartext Storage of Sensitive Information vulnerability in Paloaltonetworks Pan-Os
A vulnerability in Palo Alto Networks PAN-OS software enables an authenticated administrator to expose the plaintext values of secrets stored in the device configuration and encrypted API keys.
network
low complexity
paloaltonetworks CWE-312
4.9