Vulnerabilities > Paloaltonetworks > PAN OS

DATE CVE VULNERABILITY TITLE RISK
2016-04-12 CVE-2016-3654 Improper Input Validation vulnerability in Paloaltonetworks Pan-Os
The device management command line interface (CLI) in Palo Alto Networks PAN-OS before 5.0.18, 5.1.x before 5.1.11, 6.0.x before 6.0.13, 6.1.x before 6.1.10, and 7.0.x before 7.0.5H2 allows remote authenticated administrators to execute arbitrary OS commands via an SSH command parameter.
network
low complexity
paloaltonetworks CWE-20
critical
9.0
2015-06-02 CVE-2015-4162 Unspecified vulnerability in Paloaltonetworks Pan-Os
XML external entity (XXE) vulnerability in the management interface in PAN-OS before 5.0.16, 6.x before 6.0.8, and 6.1.x before 6.1.4 allows remote authenticated administrators to obtain sensitive information via crafted XML data.
network
low complexity
paloaltonetworks
4.0
2015-01-06 CVE-2014-3764 Cross-site Scripting vulnerability in Paloaltonetworks Pan-Os
Cross-site scripting (XSS) vulnerability in the web-based device management interface in Palo Alto Networks PAN-OS before 5.0.15, 5.1.x before 5.1.10, and 6.0.x before 6.0.6 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka Ref ID 64563.
4.3
2013-08-31 CVE-2013-5664 Cross-Site Scripting vulnerability in Paloaltonetworks Pan-Os
Cross-site scripting (XSS) vulnerability in the web-based device-management API browser in Palo Alto Networks PAN-OS before 4.1.13 and 5.0.x before 5.0.6 allows remote attackers to inject arbitrary web script or HTML via crafted data, aka Ref ID 50908.
4.3
2013-08-31 CVE-2012-6605 OS Command Injection vulnerability in Paloaltonetworks Pan-Os
The device-management command-line interface in Palo Alto Networks PAN-OS before 3.1.11 and 4.0.x before 4.0.9 allows remote authenticated users to execute arbitrary code via unspecified vectors, aka Ref ID 34896.
network
low complexity
paloaltonetworks CWE-78
critical
9.0
2013-08-31 CVE-2012-6604 OS Command Injection vulnerability in Paloaltonetworks Pan-Os
The device-management command-line interface in Palo Alto Networks PAN-OS before 3.1.11 and 4.0.x before 4.0.9 allows remote authenticated users to execute arbitrary code via unspecified vectors, aka Ref ID 35249.
network
low complexity
paloaltonetworks CWE-78
critical
9.0
2013-08-31 CVE-2012-6603 Improper Authentication vulnerability in Paloaltonetworks Pan-Os
The web management UI in Palo Alto Networks PAN-OS before 3.1.12, 4.0.x before 4.0.10, and 4.1.x before 4.1.4 allows remote attackers to bypass authentication and obtain administrator privileges via unspecified vectors, aka Ref ID 37034.
network
low complexity
paloaltonetworks CWE-287
critical
10.0
2013-08-31 CVE-2012-6602 OS Command Injection vulnerability in Paloaltonetworks Pan-Os
The device-management command-line interface in Palo Alto Networks PAN-OS before 3.1.10 and 4.0.x before 4.0.4 allows remote authenticated users to execute arbitrary commands via unspecified vectors, aka Ref ID 30122.
network
low complexity
paloaltonetworks CWE-78
critical
9.0
2013-08-31 CVE-2012-6601 OS Command Injection vulnerability in Paloaltonetworks Pan-Os
The device-management command-line interface in Palo Alto Networks PAN-OS before 3.1.12, 4.0.x before 4.0.10, and 4.1.x before 4.1.4 allows remote attackers to execute arbitrary code via unspecified vectors, aka Ref ID 36983.
network
low complexity
paloaltonetworks CWE-78
critical
10.0
2013-08-31 CVE-2012-6600 OS Command Injection vulnerability in Paloaltonetworks Pan-Os
The device-management command-line interface in Palo Alto Networks PAN-OS 4.0.x before 4.0.9 and 4.1.x before 4.1.2 allows remote authenticated users to execute arbitrary commands via unspecified vectors, aka Ref ID 34502.
network
low complexity
paloaltonetworks CWE-78
critical
9.0