Show filters
291 Total Results
Displaying 61-70 of 291
Sort by:
Attacker Value
Unknown
CVE-2023-6793
Disclosure Date: December 13, 2023 (last updated December 19, 2023)
An improper privilege management vulnerability in Palo Alto Networks PAN-OS software enables an authenticated read-only administrator to revoke active XML API keys from the firewall and disrupt XML API usage.
0
Attacker Value
Unknown
CVE-2023-6792
Disclosure Date: December 13, 2023 (last updated December 19, 2023)
An OS command injection vulnerability in the XML API of Palo Alto Networks PAN-OS software enables an authenticated API user to disrupt system processes and potentially execute arbitrary code with limited privileges on the firewall.
0
Attacker Value
Unknown
CVE-2023-6791
Disclosure Date: December 13, 2023 (last updated December 19, 2023)
A credential disclosure vulnerability in Palo Alto Networks PAN-OS software enables an authenticated read-only administrator to obtain the plaintext credentials of stored external system integrations such as LDAP, SCP, RADIUS, TACACS+, and SNMP from the web interface.
0
Attacker Value
Unknown
CVE-2023-6790
Disclosure Date: December 13, 2023 (last updated December 19, 2023)
A DOM-Based cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS software enables a remote attacker to execute a JavaScript payload in the context of an administrator’s browser when they view a specifically crafted link to the PAN-OS web interface.
0
Attacker Value
Unknown
CVE-2023-6789
Disclosure Date: December 13, 2023 (last updated December 19, 2023)
A cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS software enables a malicious authenticated read-write administrator to store a JavaScript payload using the web interface. Then, when viewed by a properly authenticated administrator, the JavaScript payload executes and disguises all associated actions as performed by that unsuspecting authenticated administrator.
0
Attacker Value
Unknown
CVE-2023-3282
Disclosure Date: November 08, 2023 (last updated November 17, 2023)
A local privilege escalation (PE) vulnerability in the Palo Alto Networks Cortex XSOAR engine software running on a Linux operating system enables a local attacker to execute programs with elevated privileges if the attacker has shell access to the engine.
0
Attacker Value
Unknown
CVE-2023-3280
Disclosure Date: September 13, 2023 (last updated October 08, 2023)
A problem with a protection mechanism in the Palo Alto Networks Cortex XDR agent on Windows devices allows a local user to disable the agent.
0
Attacker Value
Unknown
CVE-2023-38046
Disclosure Date: July 12, 2023 (last updated October 08, 2023)
A vulnerability exists in Palo Alto Networks PAN-OS software that enables an authenticated administrator with the privilege to commit a specifically created configuration to read local files and resources from the system.
0
Attacker Value
Unknown
CVE-2023-0010
Disclosure Date: June 14, 2023 (last updated October 08, 2023)
A reflected cross-site scripting (XSS) vulnerability in the Captive Portal feature of Palo Alto Networks PAN-OS software can allow a JavaScript payload to be executed in the context of an authenticated Captive Portal user’s browser when they click on a specifically crafted link.
0
Attacker Value
Unknown
CVE-2023-0009
Disclosure Date: June 14, 2023 (last updated October 08, 2023)
A local privilege escalation (PE) vulnerability in the Palo Alto Networks GlobalProtect app on Windows enables a local user to execute programs with elevated privileges.
0