Vulnerabilities > Paloaltonetworks > PAN OS > Medium

DATE CVE VULNERABILITY TITLE RISK
2021-09-08 CVE-2021-3054 Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Paloaltonetworks Pan-Os
A time-of-check to time-of-use (TOCTOU) race condition vulnerability in the Palo Alto Networks PAN-OS web interface enables an authenticated administrator with permission to upload plugins to execute arbitrary code with root user privileges.
network
high complexity
paloaltonetworks CWE-367
6.6
2021-09-08 CVE-2021-3055 XXE vulnerability in Paloaltonetworks Pan-Os
An improper restriction of XML external entity (XXE) reference vulnerability in the Palo Alto Networks PAN-OS web interface enables an authenticated administrator to read any arbitrary file from the file system and send a specifically crafted request to the firewall that causes the service to crash.
network
low complexity
paloaltonetworks CWE-611
6.5
2021-08-11 CVE-2021-3045 Argument Injection or Modification vulnerability in Paloaltonetworks Pan-Os
An OS command argument injection vulnerability in the Palo Alto Networks PAN-OS web interface enables an authenticated administrator to read any arbitrary file from the file system.
network
low complexity
paloaltonetworks CWE-88
4.9
2021-08-11 CVE-2021-3046 Improper Authentication vulnerability in Paloaltonetworks Pan-Os
An improper authentication vulnerability exists in Palo Alto Networks PAN-OS software that enables a SAML authenticated attacker to impersonate any other user in the GlobalProtect Portal and GlobalProtect Gateway when they are configured to use SAML authentication.
network
low complexity
paloaltonetworks CWE-287
6.5
2021-08-11 CVE-2021-3048 Improper Input Validation vulnerability in Paloaltonetworks Pan-Os
Certain invalid URL entries contained in an External Dynamic List (EDL) cause the Device Server daemon (devsrvr) to stop responding.
network
high complexity
paloaltonetworks CWE-20
5.9
2020-11-12 CVE-2020-1999 Improper Check for Unusual or Exceptional Conditions vulnerability in Paloaltonetworks Pan-Os
A vulnerability exists in the Palo Alto Network PAN-OS signature-based threat detection engine that allows an attacker to communicate with devices in the network in a way that is not analyzed for threats by sending data through specifically crafted TCP packets.
network
low complexity
paloaltonetworks CWE-754
5.3
2020-09-09 CVE-2020-2039 Resource Exhaustion vulnerability in Paloaltonetworks Pan-Os
An uncontrolled resource consumption vulnerability in Palo Alto Networks PAN-OS allows for a remote unauthenticated user to upload temporary files through the management web interface that are not properly deleted after the request is finished.
network
low complexity
paloaltonetworks CWE-400
5.3
2020-07-08 CVE-2020-2031 Integer Underflow (Wrap or Wraparound) vulnerability in Paloaltonetworks Pan-Os 9.1.0/9.1.1/9.1.2
An integer underflow vulnerability in the dnsproxyd component of the PAN-OS management interface allows authenticated administrators to issue a command from the command line interface that causes the component to stop responding.
network
low complexity
paloaltonetworks CWE-191
4.9
2020-07-08 CVE-2020-1982 Inadequate Encryption Strength vulnerability in Paloaltonetworks Pan-Os
Certain communication between PAN-OS and cloud-delivered services inadvertently use TLS 1.0, which is known to be a cryptographically weak protocol.
network
high complexity
paloaltonetworks CWE-326
4.8
2020-05-13 CVE-2020-2017 Cross-site Scripting vulnerability in Paloaltonetworks Pan-Os
A DOM-Based Cross Site Scripting Vulnerability exists in PAN-OS and Panorama Management Web Interfaces.
network
low complexity
paloaltonetworks CWE-79
6.1