Show filters
291 Total Results
Displaying 71-80 of 291
Sort by:
Attacker Value
Unknown

CVE-2023-0008

Disclosure Date: May 10, 2023 (last updated October 08, 2023)
A file disclosure vulnerability in Palo Alto Networks PAN-OS software enables an authenticated read-write administrator with access to the web interface to export local files from the firewall through a race condition.
Attacker Value
Unknown

CVE-2023-0007

Disclosure Date: May 10, 2023 (last updated October 08, 2023)
A cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS software on Panorama appliances enables an authenticated read-write administrator to store a JavaScript payload in the web interface that will execute in the context of another administrator’s browser when viewed.
Attacker Value
Unknown

CVE-2023-0006

Disclosure Date: April 12, 2023 (last updated October 08, 2023)
A local file deletion vulnerability in the Palo Alto Networks GlobalProtect app on Windows devices enables a user to delete system files from the endpoint with elevated privileges through a race condition.
Attacker Value
Unknown

CVE-2023-0005

Disclosure Date: April 12, 2023 (last updated October 08, 2023)
A vulnerability in Palo Alto Networks PAN-OS software enables an authenticated administrator to expose the plaintext values of secrets stored in the device configuration and encrypted API keys.
Attacker Value
Unknown

CVE-2023-0004

Disclosure Date: April 12, 2023 (last updated January 09, 2024)
A local file deletion vulnerability in Palo Alto Networks PAN-OS software enables an authenticated administrator to delete files from the local file system with elevated privileges. These files can include logs and system components that impact the integrity and availability of PAN-OS software.
Attacker Value
Unknown

CVE-2023-0003

Disclosure Date: February 08, 2023 (last updated February 14, 2025)
A file disclosure vulnerability in the Palo Alto Networks Cortex XSOAR server software enables an authenticated user with access to the web interface to read local files from the server.
Attacker Value
Unknown

CVE-2023-0002

Disclosure Date: February 08, 2023 (last updated November 08, 2023)
A problem with a protection mechanism in the Palo Alto Networks Cortex XDR agent on Windows devices allows a local user to execute privileged cytool commands that disable or uninstall the agent.
Attacker Value
Unknown

CVE-2023-0001

Disclosure Date: February 08, 2023 (last updated November 08, 2023)
An information exposure vulnerability in the Palo Alto Networks Cortex XDR agent on Windows devices allows a local system administrator to disclose the admin password for the agent in cleartext, which bad actors can then use to execute privileged cytool commands that disable or uninstall the agent.
Attacker Value
Unknown

CVE-2022-0031

Disclosure Date: November 09, 2022 (last updated December 22, 2024)
A local privilege escalation (PE) vulnerability in the Palo Alto Networks Cortex XSOAR engine software running on a Linux operating system allows a local attacker with shell access to the engine to execute programs with elevated privileges.
Attacker Value
Unknown

CVE-2022-0030

Disclosure Date: October 12, 2022 (last updated October 08, 2023)
An authentication bypass vulnerability in the Palo Alto Networks PAN-OS 8.1 web interface allows a network-based attacker with specific knowledge of the target firewall or Panorama appliance to impersonate an existing PAN-OS administrator and perform privileged actions.