Vulnerabilities > Paloaltonetworks > High

DATE CVE VULNERABILITY TITLE RISK
2021-02-10 CVE-2021-3033 Improper Verification of Cryptographic Signature vulnerability in Paloaltonetworks Prisma Cloud
An improper verification of cryptographic signature vulnerability exists in the Palo Alto Networks Prisma Cloud Compute console.
network
low complexity
paloaltonetworks CWE-347
7.5
2020-12-09 CVE-2020-2049 Uncontrolled Search Path Element vulnerability in Paloaltonetworks Cortex XDR Agent 7.1/7.1.2/7.2
A local privilege escalation vulnerability exists in Palo Alto Networks Cortex XDR Agent on the Windows platform that allows an authenticated local Windows user to execute programs with SYSTEM privileges.
local
low complexity
paloaltonetworks CWE-427
7.2
2020-09-09 CVE-2020-2041 Unspecified vulnerability in Paloaltonetworks Pan-Os
An insecure configuration of the appweb daemon of Palo Alto Networks PAN-OS 8.1 allows a remote unauthenticated user to send a specifically crafted request to the device that causes the appweb service to crash.
network
low complexity
paloaltonetworks
7.8
2020-09-09 CVE-2020-2038 OS Command Injection vulnerability in Paloaltonetworks Pan-Os
An OS Command Injection vulnerability in the PAN-OS management interface that allows authenticated administrators to execute arbitrary OS commands with root privileges.
network
low complexity
paloaltonetworks CWE-78
7.2
2020-05-13 CVE-2020-2016 Race Condition vulnerability in Paloaltonetworks Pan-Os
A race condition due to insecure creation of a file in a temporary directory vulnerability in PAN-OS allows for root privilege escalation from a limited linux user account.
8.5
2020-05-13 CVE-2020-2011 Improper Input Validation vulnerability in Paloaltonetworks Pan-Os
An improper input validation vulnerability in the configuration daemon of Palo Alto Networks PAN-OS Panorama allows for a remote unauthenticated user to send a specifically crafted registration request to the device that causes the configuration service to crash.
network
low complexity
paloaltonetworks CWE-20
7.8
2020-05-13 CVE-2020-2003 Unspecified vulnerability in Paloaltonetworks Pan-Os
An external control of filename vulnerability in the command processing of PAN-OS allows an authenticated administrator to delete arbitrary system files affecting the integrity of the system or causing denial of service to all PAN-OS services.
network
low complexity
paloaltonetworks
8.5
2020-05-13 CVE-2020-2001 Out-of-bounds Write vulnerability in Paloaltonetworks Pan-Os
An external control of path and data vulnerability in the Palo Alto Networks PAN-OS Panorama XSLT processing logic that allows an unauthenticated user with network access to PAN-OS management interface to write attacker supplied file on the system and elevate privileges.
network
low complexity
paloaltonetworks CWE-787
7.5
2020-04-08 CVE-2020-1989 Improper Privilege Management vulnerability in Paloaltonetworks Globalprotect 5.0/5.0.4/5.1
An incorrect privilege assignment vulnerability when writing application-specific files in the Palo Alto Networks Global Protect Agent for Linux on ARM platform allows a local authenticated user to gain root privileges on the system.
local
low complexity
paloaltonetworks CWE-269
7.2
2020-04-08 CVE-2020-1988 Unquoted Search Path or Element vulnerability in Paloaltonetworks Globalprotect
An unquoted search path vulnerability in the Windows release of Global Protect Agent allows an authenticated local user with file creation privileges on the root of the OS disk (C:\) or to Program Files directory to gain system privileges.
local
low complexity
paloaltonetworks CWE-428
7.2