Vulnerabilities > Paloaltonetworks > Medium

DATE CVE VULNERABILITY TITLE RISK
2020-11-12 CVE-2020-1999 Improper Check for Unusual or Exceptional Conditions vulnerability in Paloaltonetworks Pan-Os
A vulnerability exists in the Palo Alto Network PAN-OS signature-based threat detection engine that allows an attacker to communicate with devices in the network in a way that is not analyzed for threats by sending data through specifically crafted TCP packets.
network
low complexity
paloaltonetworks CWE-754
5.3
2020-09-09 CVE-2020-2039 Resource Exhaustion vulnerability in Paloaltonetworks Pan-Os
An uncontrolled resource consumption vulnerability in Palo Alto Networks PAN-OS allows for a remote unauthenticated user to upload temporary files through the management web interface that are not properly deleted after the request is finished.
network
low complexity
paloaltonetworks CWE-400
5.3
2020-07-08 CVE-2020-2031 Integer Underflow (Wrap or Wraparound) vulnerability in Paloaltonetworks Pan-Os 9.1.0/9.1.1/9.1.2
An integer underflow vulnerability in the dnsproxyd component of the PAN-OS management interface allows authenticated administrators to issue a command from the command line interface that causes the component to stop responding.
network
low complexity
paloaltonetworks CWE-191
4.9
2020-07-08 CVE-2020-1982 Inadequate Encryption Strength vulnerability in Paloaltonetworks Pan-Os
Certain communication between PAN-OS and cloud-delivered services inadvertently use TLS 1.0, which is known to be a cryptographically weak protocol.
network
high complexity
paloaltonetworks CWE-326
4.8
2020-06-10 CVE-2020-2033 Authentication Bypass by Spoofing vulnerability in Paloaltonetworks Globalprotect
When the pre-logon feature is enabled, a missing certification validation in Palo Alto Networks GlobalProtect app can disclose the pre-logon authentication cookie to a man-in-the-middle attacker on the same local area network segment with the ability to manipulate ARP or to conduct ARP spoofing attacks.
high complexity
paloaltonetworks CWE-290
5.3
2020-05-13 CVE-2020-2017 Cross-site Scripting vulnerability in Paloaltonetworks Pan-Os
A DOM-Based Cross Site Scripting Vulnerability exists in PAN-OS and Panorama Management Web Interfaces.
network
low complexity
paloaltonetworks CWE-79
6.1
2020-05-13 CVE-2020-2005 Cross-site Scripting vulnerability in Paloaltonetworks Pan-Os
A cross-site scripting (XSS) vulnerability exists when visiting malicious websites with the Palo Alto Networks GlobalProtect Clientless VPN that can compromise the user's active session.
network
low complexity
paloaltonetworks CWE-79
6.1
2020-05-13 CVE-2020-2004 Information Exposure Through Log Files vulnerability in Paloaltonetworks Globalprotect
Under certain circumstances a user's password may be logged in cleartext in the PanGPS.log diagnostic file when logs are collected for troubleshooting on GlobalProtect app (also known as GlobalProtect Agent) for MacOS and Windows.
local
low complexity
paloaltonetworks CWE-532
5.5
2020-05-13 CVE-2020-2003 Unspecified vulnerability in Paloaltonetworks Pan-Os
An external control of filename vulnerability in the command processing of PAN-OS allows an authenticated administrator to delete arbitrary system files affecting the integrity of the system or causing denial of service to all PAN-OS services.
network
low complexity
paloaltonetworks
6.5
2020-05-13 CVE-2020-1997 Open Redirect vulnerability in Paloaltonetworks Pan-Os
An open redirection vulnerability in the GlobalProtect component of Palo Alto Networks PAN-OS allows an attacker to specify an arbitrary redirection target away from the trusted GlobalProtect gateway.
network
low complexity
paloaltonetworks CWE-601
6.1