paloaltonetworks

310 tracked vulnerabilities.

CVE-2020-2018 CRITICAL
PAN-OS 7.1.0-7.1.25 - Authentication Bypass via Panorama Context Switching
May 13, 2020
CVSS 9.0
EPSS 0.00
CVE-2020-2017 HIGH
PAN-OS 7.1.0-7.1.25 - Authenticated DOM-Based Cross-Site Scripting
May 13, 2020
CVSS 8.8
EPSS 0.00
CVE-2020-2016 HIGH
PAN-OS < 7.1.26, < 8.1.13, < 9.0.6 - Privilege Escalation via Insecure Temporary File Creation
May 13, 2020
CVSS 7.0
EPSS 0.00
CVE-2020-2015 HIGH
PAN-OS 7.1.0-7.1.25 - Authenticated Buffer Overflow in Management Server
May 13, 2020
CVSS 8.8
EPSS 0.02
CVE-2020-2014 HIGH
PAN-OS 7.1.0-7.1.25 - Authenticated OS Command Injection
May 13, 2020
CVSS 8.8
EPSS 0.05
CVE-2020-2013 HIGH
Palo Alto Networks PAN-OS 7.1.0-7.1.25 - Authenticated Cleartext Transmission of Session Cookie
May 13, 2020
CVSS 8.3
EPSS 0.00
CVE-2020-2012 HIGH
Palo Alto Networks Pan-OS 7.1.0-7.1.25 - Unauthenticated XML External Entity Injection
May 13, 2020
CVSS 7.5
EPSS 0.04
CVE-2020-2011 HIGH
Palo Alto Networks PAN-OS 7.1.0-7.1.25 - Unauthenticated Denial of Service via Crafted Registration Request
May 13, 2020
CVSS 7.5
EPSS 0.01
CVE-2020-2010 HIGH
PAN-OS 7.1.0-7.1.25 - Authenticated OS Command Injection
May 13, 2020
CVSS 7.2
EPSS 0.03
CVE-2020-2009 HIGH
Palo Alto Networks PAN-OS <8.1.14, <9.0.7 - Remote Code Execution
May 13, 2020
CVSS 7.2
EPSS 0.02
CVE-2020-2008 HIGH
PAN-OS 7.1.0-7.1.25 and 8.0 - Authenticated OS Command Injection and Arbitrary File Deletion
May 13, 2020
CVSS 7.2
EPSS 0.03
CVE-2020-2007 HIGH
PAN-OS 7.1.0-7.1.25 - Authenticated OS Command Injection
May 13, 2020
CVSS 7.2
EPSS 0.04
CVE-2020-2006 HIGH
PAN-OS 7.1.0-7.1.25 and 8.0 - Authenticated Stack-based Buffer Overflow
May 13, 2020
CVSS 7.2
EPSS 0.02
CVE-2020-2005 HIGH
PAN-OS 7.1.0-7.1.25 - Cross-Site Scripting via GlobalProtect Clientless VPN
May 13, 2020
CVSS 7.1
EPSS 0.01
CVE-2020-2004 MEDIUM
GlobalProtect 5.0.0-5.0.8 and 5.1.0-5.1.1 - Sensitive Information Disclosure in PanGPS.log
May 13, 2020
CVSS 6.8
EPSS 0.00
CVE-2020-2003 MEDIUM
PAN-OS 7.1.0-7.1.25 - Authenticated Arbitrary File Deletion via Command Processing
May 13, 2020
CVSS 6.5
EPSS 0.00
CVE-2020-2002 HIGH
PAN-OS 7.1.0-7.1.25 - Authentication Bypass via Kerberos KDC Spoofing
May 13, 2020
CVSS 8.1
EPSS 0.01
CVE-2020-2001 HIGH
Palo Alto Networks PAN-OS 7.1.0-7.1.25 - Unauthenticated Out-of-bounds Write via XSLT Processing
May 13, 2020
CVSS 8.1
EPSS 0.02
CVE-2020-1998 MEDIUM
PAN-OS 7.1.0-7.1.25 - Authentication Bypass via SAML Username Sharing
May 13, 2020
CVSS 5.4
EPSS 0.00
CVE-2020-1997 MEDIUM
PAN-OS 7.1.0-7.1.25 - URL Redirection to Untrusted Site via GlobalProtect Component
May 13, 2020
CVSS 5.3
EPSS 0.00
CVE-2020-1996 MEDIUM
PAN-OS 7.1.0-7.1.25 - Unauthenticated Log Injection in Management Server
May 13, 2020
CVSS 5.3
EPSS 0.01
CVE-2020-1995 MEDIUM
PAN-OS 9.1.0-9.1.1 - Authenticated Denial of Service via rasmgr Daemon NULL Pointer Dereference
May 13, 2020
CVSS 4.9
EPSS 0.00
CVE-2020-1994 MEDIUM
PAN-OS <8.1.13, <9.0.7 - Local Privilege Escalation
May 13, 2020
CVSS 4.1
EPSS 0.00
CVE-2020-1993 LOW
PAN-OS <8.1.14, <9.0.8 - Session Fixation
May 13, 2020
CVSS 3.7
EPSS 0.00
CVE-2020-1992 HIGH
PAN-OS 9.0.0-9.0.6 - Use-After-Free in Varrcvr Daemon via WildFire Log Forwarding
Apr 08, 2020
CVSS 8.1
EPSS 0.02