Vulnerabilities > Paloaltonetworks > High

DATE CVE VULNERABILITY TITLE RISK
2021-11-10 CVE-2021-3056 Out-of-bounds Write vulnerability in Paloaltonetworks Pan-Os
A memory corruption vulnerability in Palo Alto Networks PAN-OS GlobalProtect Clientless VPN enables an authenticated attacker to execute arbitrary code with root user privileges during SAML authentication.
network
low complexity
paloaltonetworks CWE-787
8.8
2021-11-10 CVE-2021-3058 OS Command Injection vulnerability in Paloaltonetworks Pan-Os
An OS command injection vulnerability in the Palo Alto Networks PAN-OS web interface enables an authenticated administrator with permissions to use XML API the ability to execute arbitrary OS commands to escalate privileges.
network
low complexity
paloaltonetworks CWE-78
7.2
2021-11-10 CVE-2021-3059 OS Command Injection vulnerability in Paloaltonetworks Pan-Os
An OS command injection vulnerability in the Palo Alto Networks PAN-OS management interface exists when performing dynamic updates.
network
high complexity
paloaltonetworks CWE-78
8.1
2021-11-10 CVE-2021-3060 OS Command Injection vulnerability in Paloaltonetworks Pan-Os
An OS command injection vulnerability in the Simple Certificate Enrollment Protocol (SCEP) feature of PAN-OS software allows an unauthenticated network-based attacker with specific knowledge of the firewall configuration to execute arbitrary code with root user privileges.
network
high complexity
paloaltonetworks CWE-78
8.1
2021-11-10 CVE-2021-3061 OS Command Injection vulnerability in Paloaltonetworks Pan-Os
An OS command injection vulnerability in the Palo Alto Networks PAN-OS command line interface (CLI) enables an authenticated administrator with access to the CLI to execute arbitrary OS commands to escalate privileges.
network
low complexity
paloaltonetworks CWE-78
7.2
2021-11-10 CVE-2021-3062 Unspecified vulnerability in Paloaltonetworks Pan-Os
An improper access control vulnerability in PAN-OS software enables an attacker with authenticated access to GlobalProtect portals and gateways to connect to the EC2 instance metadata endpoint for VM-Series firewalls hosted on Amazon AWS.
network
low complexity
paloaltonetworks
8.8
2021-11-10 CVE-2021-3063 Improper Handling of Exceptional Conditions vulnerability in Paloaltonetworks Pan-Os
An improper handling of exceptional conditions vulnerability exists in Palo Alto Networks GlobalProtect portal and gateway interfaces that enables an unauthenticated network-based attacker to send specifically crafted traffic to a GlobalProtect interface that causes the service to stop responding.
network
low complexity
paloaltonetworks CWE-755
7.5
2021-09-08 CVE-2021-3051 Improper Verification of Cryptographic Signature vulnerability in Paloaltonetworks Cortex Xsoar
An improper verification of cryptographic signature vulnerability exists in Cortex XSOAR SAML authentication that enables an unauthenticated network-based attacker with specific knowledge of the Cortex XSOAR instance to access protected resources and perform unauthorized actions on the Cortex XSOAR server.
network
high complexity
paloaltonetworks CWE-347
8.1
2021-09-08 CVE-2021-3053 Improper Handling of Exceptional Conditions vulnerability in Paloaltonetworks Pan-Os
An improper handling of exceptional conditions vulnerability exists in the Palo Alto Networks PAN-OS dataplane that enables an unauthenticated network-based attacker to send specifically crafted traffic through the firewall that causes the service to crash.
network
low complexity
paloaltonetworks CWE-755
7.5
2021-08-11 CVE-2021-3050 OS Command Injection vulnerability in Paloaltonetworks Pan-Os
An OS command injection vulnerability in the Palo Alto Networks PAN-OS web interface enables an authenticated administrator to execute arbitrary OS commands to escalate privileges.
network
low complexity
paloaltonetworks CWE-78
8.8