Vulnerabilities > Paloaltonetworks > PAN OS > High

DATE CVE VULNERABILITY TITLE RISK
2024-09-11 CVE-2024-8686 OS Command Injection vulnerability in Paloaltonetworks Pan-Os
A command injection vulnerability in Palo Alto Networks PAN-OS software enables an authenticated administrator to bypass system restrictions and run arbitrary commands as root on the firewall.
network
low complexity
paloaltonetworks CWE-78
7.2
2024-09-11 CVE-2024-8687 Unspecified vulnerability in Paloaltonetworks Pan-Os
An information exposure vulnerability exists in Palo Alto Networks PAN-OS software that enables a GlobalProtect end user to learn both the configured GlobalProtect uninstall password and the configured disable or disconnect passcode.
network
low complexity
paloaltonetworks
7.1
2024-09-11 CVE-2024-8691 Incorrect Authorization vulnerability in Paloaltonetworks Pan-Os
A vulnerability in the GlobalProtect portal in Palo Alto Networks PAN-OS software enables a malicious authenticated GlobalProtect user to impersonate another GlobalProtect user.
network
low complexity
paloaltonetworks CWE-863
8.1
2022-10-12 CVE-2022-0030 Authentication Bypass by Spoofing vulnerability in Paloaltonetworks Pan-Os
An authentication bypass vulnerability in the Palo Alto Networks PAN-OS 8.1 web interface allows a network-based attacker with specific knowledge of the target firewall or Panorama appliance to impersonate an existing PAN-OS administrator and perform privileged actions.
network
high complexity
paloaltonetworks CWE-290
8.1
2021-11-10 CVE-2021-3056 Out-of-bounds Write vulnerability in Paloaltonetworks Pan-Os
A memory corruption vulnerability in Palo Alto Networks PAN-OS GlobalProtect Clientless VPN enables an authenticated attacker to execute arbitrary code with root user privileges during SAML authentication.
8.5
2021-11-10 CVE-2021-3059 OS Command Injection vulnerability in Paloaltonetworks Pan-Os
An OS command injection vulnerability in the Palo Alto Networks PAN-OS management interface exists when performing dynamic updates.
network
high complexity
paloaltonetworks CWE-78
7.6
2021-09-08 CVE-2021-3053 Improper Handling of Exceptional Conditions vulnerability in Paloaltonetworks Pan-Os
An improper handling of exceptional conditions vulnerability exists in the Palo Alto Networks PAN-OS dataplane that enables an unauthenticated network-based attacker to send specifically crafted traffic through the firewall that causes the service to crash.
7.1
2021-09-08 CVE-2021-3054 Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Paloaltonetworks Pan-Os
A time-of-check to time-of-use (TOCTOU) race condition vulnerability in the Palo Alto Networks PAN-OS web interface enables an authenticated administrator with permission to upload plugins to execute arbitrary code with root user privileges.
8.5
2021-09-08 CVE-2021-3055 XXE vulnerability in Paloaltonetworks Pan-Os
An improper restriction of XML external entity (XXE) reference vulnerability in the Palo Alto Networks PAN-OS web interface enables an authenticated administrator to read any arbitrary file from the file system and send a specifically crafted request to the firewall that causes the service to crash.
network
low complexity
paloaltonetworks CWE-611
7.5
2020-09-09 CVE-2020-2041 Unspecified vulnerability in Paloaltonetworks Pan-Os
An insecure configuration of the appweb daemon of Palo Alto Networks PAN-OS 8.1 allows a remote unauthenticated user to send a specifically crafted request to the device that causes the appweb service to crash.
network
low complexity
paloaltonetworks
7.8