Show filters
7 Total Results
Displaying 1-7 of 7
Sort by:
Attacker Value
Very High

CVE-2024-3400

Disclosure Date: April 12, 2024 (last updated December 21, 2024)
A command injection as a result of arbitrary file creation vulnerability in the GlobalProtect feature of Palo Alto Networks PAN-OS software for specific PAN-OS versions and distinct feature configurations may enable an unauthenticated attacker to execute arbitrary code with root privileges on the firewall. Cloud NGFW, Panorama appliances, and Prisma Access are not impacted by this vulnerability.
Attacker Value
Unknown

CVE-2024-8687

Disclosure Date: September 11, 2024 (last updated October 03, 2024)
An information exposure vulnerability exists in Palo Alto Networks PAN-OS software that enables a GlobalProtect end user to learn both the configured GlobalProtect uninstall password and the configured disable or disconnect passcode. After the password or passcode is known, end users can uninstall, disable, or disconnect GlobalProtect even if the GlobalProtect app configuration would not normally permit them to do so.
Attacker Value
Unknown

CVE-2024-0009

Disclosure Date: February 14, 2024 (last updated December 21, 2024)
An improper verification vulnerability in the GlobalProtect gateway feature of Palo Alto Networks PAN-OS software enables a malicious user with stolen credentials to establish a VPN connection from an unauthorized IP address.
Attacker Value
Unknown

CVE-2023-6791

Disclosure Date: December 13, 2023 (last updated December 19, 2023)
A credential disclosure vulnerability in Palo Alto Networks PAN-OS software enables an authenticated read-only administrator to obtain the plaintext credentials of stored external system integrations such as LDAP, SCP, RADIUS, TACACS+, and SNMP from the web interface.
Attacker Value
Unknown

CVE-2023-6790

Disclosure Date: December 13, 2023 (last updated December 19, 2023)
A DOM-Based cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS software enables a remote attacker to execute a JavaScript payload in the context of an administrator’s browser when they view a specifically crafted link to the PAN-OS web interface.
Attacker Value
Unknown

CVE-2023-38046

Disclosure Date: July 12, 2023 (last updated October 08, 2023)
A vulnerability exists in Palo Alto Networks PAN-OS software that enables an authenticated administrator with the privilege to commit a specifically created configuration to read local files and resources from the system.
Attacker Value
Unknown

CVE-2023-0008

Disclosure Date: May 10, 2023 (last updated October 08, 2023)
A file disclosure vulnerability in Palo Alto Networks PAN-OS software enables an authenticated read-write administrator with access to the web interface to export local files from the firewall through a race condition.