<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Palo Alto Networks PAN-OS (High+Critical)</title>
  <link>https://cvedaily.com/pages/tags/panos.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/panos-severe.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Palo Alto Networks PAN-OS (High+Critical)</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:48 +0000</lastBuildDate>
  <item>
    <title>[Critical] CVE-2026-0257 – Authentication bypass vulnerabilities in the GlobalProtect portal and gateway of...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-0257</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-0257</guid>
    <pubDate>Wed, 13 May 2026 19:17:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-0257</strong></p>
  <p>Authentication bypass vulnerabilities in the GlobalProtect portal and gateway of Palo Alto Networks PAN-OS® software allows the attacker to bypass security restrictions and establish an unauthorized VPN connection.  Panorama and Cloud NGFW are not impacted by these issues.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-565</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-0257">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-0265 – An authentication bypass vulnerability in Palo Alto Networks PAN-OS® software en...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-0265</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-0265</guid>
    <pubDate>Wed, 13 May 2026 18:16:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-0265</strong></p>
  <p>An authentication bypass vulnerability in Palo Alto Networks PAN-OS® software enables an unauthenticated attacker with network access to bypass authentication controls when Cloud Authentication Service (CAS) is enabled.    The risk is higher if CAS is enabled on the management interface and lower when any other login interfaces are used.  The risk of this issue is greatly reduced if you secure ac…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-347</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-0265">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-0264 – A buffer overflow vulnerability in the DNS proxy and DNS Server features of Palo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-0264</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-0264</guid>
    <pubDate>Wed, 13 May 2026 18:16:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-0264</strong></p>
  <p>A buffer overflow vulnerability in the DNS proxy and DNS Server features of Palo Alto Networks PAN-OS® Software allows an unauthenticated attacker with network access to cause a denial of service (DoS) condition (all PAN-OS platforms except Cloud NGFW and Prisma Access) or potentially execute arbitrary code by sending specially crafted network traffic (PA-Series hardware only).     Panorama, Clou…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-122</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-0264">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-0263 – A buffer overflow vulnerability in the IKEv2 processing of Palo Alto Networks PA...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-0263</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-0263</guid>
    <pubDate>Wed, 13 May 2026 18:16:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-0263</strong></p>
  <p>A buffer overflow vulnerability in the IKEv2 processing of Palo Alto Networks PAN-OS® software allows an unauthenticated network-based attacker to execute arbitrary code with elevated privileges on the firewall, or cause a denial of service (DoS) condition.   Panorama, Cloud NGFW, and Prisma® Access are not impacted by these vulnerabilities.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-0263">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-0300 – A buffer overflow vulnerability in the User-ID™ Authentication Portal (aka Capti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-0300</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-0300</guid>
    <pubDate>Wed, 06 May 2026 19:16:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-0300</strong></p>
  <p>A buffer overflow vulnerability in the User-ID™ Authentication Portal (aka Captive Portal) service of Palo Alto Networks PAN-OS software allows an unauthenticated attacker to execute arbitrary code with root privileges on the PA-Series and VM-Series firewalls by sending specially crafted packets.   The risk of this issue is greatly reduced if you secure access to the User-ID™ Authentication Porta…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-0300">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-0227 – A vulnerability in Palo Alto Networks PAN-OS software enables an unauthenticated...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-0227</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-0227</guid>
    <pubDate>Thu, 15 Jan 2026 19:16:05 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-0227</strong></p>
  <p>A vulnerability in Palo Alto Networks PAN-OS software enables an unauthenticated attacker to cause a denial of service (DoS) to the firewall. Repeated attempts to trigger this issue results in the firewall entering into maintenance mode.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-754</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-0227">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-4615 – An improper input neutralization vulnerability in the management web interface o...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-4615</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-4615</guid>
    <pubDate>Thu, 09 Oct 2025 19:15:43 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-4615</strong></p>
  <p>An improper input neutralization vulnerability in the management web interface of the Palo Alto Networks PAN-OS® software enables an authenticated administrator to bypass system restrictions and execute arbitrary commands.  The security risk posed by this issue is significantly minimized when CLI access is restricted to a limited group of administrators.  Cloud NGFW and Prisma® Access are not aff…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-83</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-4615">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-4231 – A command injection vulnerability in Palo Alto Networks PAN-OS® enables an authe...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-4231</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-4231</guid>
    <pubDate>Fri, 13 Jun 2025 00:15:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-4231</strong></p>
  <p>A command injection vulnerability in Palo Alto Networks PAN-OS® enables an authenticated administrative user to perform actions as the root user.  The attacker must have network access to the management web interface and successfully authenticate to exploit this issue.  Cloud NGFW and Prisma Access are not impacted by this vulnerability.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-4231">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-4230 – A command injection vulnerability in Palo Alto Networks PAN-OS® software enables...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-4230</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-4230</guid>
    <pubDate>Fri, 13 Jun 2025 00:15:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-4230</strong></p>
  <p>A command injection vulnerability in Palo Alto Networks PAN-OS® software enables an authenticated administrator to bypass system restrictions and run arbitrary commands as a root user. To be able to exploit this issue, the user must have access to the PAN-OS CLI.  The security risk posed by this issue is significantly minimized when CLI access is restricted to a limited group of administrators.…</p>
  <p><strong>CVSS:</strong> 8.4 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-4230">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-0130 – A missing exception check in Palo Alto Networks PAN-OS® software with the web pr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-0130</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-0130</guid>
    <pubDate>Wed, 14 May 2025 18:15:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-0130</strong></p>
  <p>A missing exception check in Palo Alto Networks PAN-OS® software with the web proxy feature enabled allows an unauthenticated attacker to send a burst of maliciously crafted packets that causes the firewall to become unresponsive and eventually reboot. Repeated successful attempts to trigger this condition will cause the firewall to enter maintenance mode.    This issue does not affect Cloud NGFW…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-754</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-0130">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-0128 – A denial-of-service (DoS) vulnerability in the Simple Certificate Enrollment Pro...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-0128</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-0128</guid>
    <pubDate>Fri, 11 Apr 2025 02:15:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-0128</strong></p>
  <p>A denial-of-service (DoS) vulnerability in the Simple Certificate Enrollment Protocol (SCEP) authentication feature of Palo Alto Networks PAN-OS® software enables an unauthenticated attacker to initiate system reboots using a maliciously crafted packet. Repeated attempts to initiate a reboot causes the firewall to enter maintenance mode.  Cloud NGFW is not affected by this vulnerability. Prisma®…</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-754</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-0128">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-0127 – A command injection vulnerability in Palo Alto Networks PAN-OS® software enables...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-0127</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-0127</guid>
    <pubDate>Fri, 11 Apr 2025 02:15:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-0127</strong></p>
  <p>A command injection vulnerability in Palo Alto Networks PAN-OS® software enables an authenticated administrator to bypass system restrictions and run arbitrary commands as a root user. This issue is only applicable to PAN-OS VM-Series. This issue does not affect firewalls that are already deployed.  Cloud NGFW and Prisma® Access are not affected by this vulnerability.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-0127">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-0114 – A Denial of Service (DoS) vulnerability in the GlobalProtect feature of Palo Alt...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-0114</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-0114</guid>
    <pubDate>Wed, 12 Mar 2025 19:15:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-0114</strong></p>
  <p>A Denial of Service (DoS) vulnerability in the GlobalProtect feature of Palo Alto Networks PAN-OS software enables an unauthenticated attacker to render the service unavailable by sending a large number of specially crafted packets over a period of time. This issue affects both the GlobalProtect portal and the GlobalProtect gateway.  This issue does not apply to Cloud NGFWs or Prisma Access softw…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-0114">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-0110 – A command injection vulnerability in the Palo Alto Networks PAN-OS OpenConfig pl...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-0110</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-0110</guid>
    <pubDate>Wed, 12 Feb 2025 21:15:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-0110</strong></p>
  <p>A command injection vulnerability in the Palo Alto Networks PAN-OS OpenConfig plugin enables an authenticated administrator with the ability to make gNMI requests to the PAN-OS management web interface to bypass system restrictions and run arbitrary commands. The commands are run as the “__openconfig” user (which has the Device Administrator role) on the firewall.  You can greatly reduce the risk…</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-0110">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-0108 – An authentication bypass in the Palo Alto Networks PAN-OS software enables an un...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-0108</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-0108</guid>
    <pubDate>Wed, 12 Feb 2025 21:15:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-0108</strong></p>
  <p>An authentication bypass in the Palo Alto Networks PAN-OS software enables an unauthenticated attacker with network access to the management web interface to bypass the authentication otherwise required by the PAN-OS management web interface and invoke certain PHP scripts. While invoking these PHP scripts does not enable remote code execution, it can negatively impact integrity and confidentialit…</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-306</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-0108">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-3393 – A Denial of Service vulnerability in the DNS Security feature of Palo Alto Netwo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-3393</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-3393</guid>
    <pubDate>Fri, 27 Dec 2024 10:15:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-3393</strong></p>
  <p>A Denial of Service vulnerability in the DNS Security feature of Palo Alto Networks PAN-OS software allows an unauthenticated attacker to send a malicious packet through the data plane of the firewall that reboots the firewall. Repeated attempts to trigger this condition will cause the firewall to enter maintenance mode.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-754</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-3393">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-9474 – A privilege escalation vulnerability in Palo Alto Networks PAN-OS software allow...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-9474</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-9474</guid>
    <pubDate>Mon, 18 Nov 2024 16:15:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-9474</strong></p>
  <p>A privilege escalation vulnerability in Palo Alto Networks PAN-OS software allows a PAN-OS administrator with access to the management web interface to perform actions on the firewall with root privileges.  Cloud NGFW and Prisma Access are not impacted by this vulnerability.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-9474">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-0012 – An authentication bypass in Palo Alto Networks PAN-OS software enables an unauth...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-0012</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-0012</guid>
    <pubDate>Mon, 18 Nov 2024 16:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-0012</strong></p>
  <p>An authentication bypass in Palo Alto Networks PAN-OS software enables an unauthenticated attacker with network access to the management web interface to gain PAN-OS administrator privileges to perform administrative actions, tamper with the configuration, or exploit other authenticated privilege escalation vulnerabilities like  CVE-2024-9474 https://security.paloaltonetworks.com/CVE-2024-9474 .…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-306</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-0012">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-9472 – A null pointer dereference in Palo Alto Networks PAN-OS software on PA-800 Serie...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-9472</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-9472</guid>
    <pubDate>Thu, 14 Nov 2024 10:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-9472</strong></p>
  <p>A null pointer dereference in Palo Alto Networks PAN-OS software on PA-800 Series, PA-3200 Series, PA-5200 Series, and PA-7000 Series hardware platforms when Decryption policy is enabled allows an unauthenticated attacker to crash PAN-OS by sending specific traffic through the data plane, resulting in a denial of service (DoS) condition. Repeated attempts to trigger this condition will result in…</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-9472">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-2551 – A null pointer dereference vulnerability in Palo Alto Networks PAN-OS software e...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-2551</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-2551</guid>
    <pubDate>Thu, 14 Nov 2024 10:15:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-2551</strong></p>
  <p>A null pointer dereference vulnerability in Palo Alto Networks PAN-OS software enables an unauthenticated attacker to stop a core system service on the firewall by sending a crafted packet through the data plane that causes a denial of service (DoS) condition. Repeated attempts to trigger this condition result in the firewall entering maintenance mode.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-2551">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-2550 – A null pointer dereference vulnerability in the GlobalProtect gateway in Palo Al...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-2550</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-2550</guid>
    <pubDate>Thu, 14 Nov 2024 10:15:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-2550</strong></p>
  <p>A null pointer dereference vulnerability in the GlobalProtect gateway in Palo Alto Networks PAN-OS software enables an unauthenticated attacker to stop the GlobalProtect service on the firewall by sending a specially crafted packet that causes a denial of service (DoS) condition. Repeated attempts to trigger this condition result in the firewall entering maintenance mode.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-2550">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-9468 – A memory corruption vulnerability in Palo Alto Networks PAN-OS software allows a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-9468</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-9468</guid>
    <pubDate>Wed, 09 Oct 2024 17:15:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-9468</strong></p>
  <p>A memory corruption vulnerability in Palo Alto Networks PAN-OS software allows an unauthenticated attacker to crash PAN-OS due to a crafted packet through the data plane, resulting in a denial of service (DoS) condition. Repeated attempts to trigger this condition will result in PAN-OS entering maintenance mode.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-9468">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-8691 – A vulnerability in the GlobalProtect portal in Palo Alto Networks PAN-OS softwar...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-8691</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-8691</guid>
    <pubDate>Wed, 11 Sep 2024 17:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-8691</strong></p>
  <p>A vulnerability in the GlobalProtect portal in Palo Alto Networks PAN-OS software enables a malicious authenticated GlobalProtect user to impersonate another GlobalProtect user. Active GlobalProtect users impersonated by an attacker who is exploiting this vulnerability are disconnected from GlobalProtect. Upon exploitation, PAN-OS logs indicate that the impersonated user authenticated to GlobalPr…</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-8691">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-8687 – An information exposure vulnerability exists in Palo Alto Networks PAN-OS softwa...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-8687</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-8687</guid>
    <pubDate>Wed, 11 Sep 2024 17:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-8687</strong></p>
  <p>An information exposure vulnerability exists in Palo Alto Networks PAN-OS software that enables a GlobalProtect end user to learn both the configured GlobalProtect uninstall password and the configured disable or disconnect passcode. After the password or passcode is known, end users can uninstall, disable, or disconnect GlobalProtect even if the GlobalProtect app configuration would not normally…</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-497</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-8687">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-8686 – A command injection vulnerability in Palo Alto Networks PAN-OS software enables ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-8686</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-8686</guid>
    <pubDate>Wed, 11 Sep 2024 17:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-8686</strong></p>
  <p>A command injection vulnerability in Palo Alto Networks PAN-OS software enables an authenticated administrator to bypass system restrictions and run arbitrary commands as root on the firewall.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-8686">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-3400 – A command injection as a result of arbitrary file creation vulnerability in the ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-3400</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-3400</guid>
    <pubDate>Fri, 12 Apr 2024 08:15:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-3400</strong></p>
  <p>A command injection as a result of arbitrary file creation vulnerability in the GlobalProtect feature of Palo Alto Networks PAN-OS software for specific PAN-OS versions and distinct feature configurations may enable an unauthenticated attacker to execute arbitrary code with root privileges on the firewall.  Cloud NGFW, Panorama appliances, and Prisma Access are not impacted by this vulnerability.</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-3400">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-3385 – A packet processing mechanism in Palo Alto Networks PAN-OS software enables a re...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-3385</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-3385</guid>
    <pubDate>Wed, 10 Apr 2024 17:15:57 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-3385</strong></p>
  <p>A packet processing mechanism in Palo Alto Networks PAN-OS software enables a remote attacker to reboot hardware-based firewalls. Repeated attacks eventually cause the firewall to enter maintenance mode, which requires manual intervention to bring the firewall back online.  This affects the following hardware firewall models: - PA-5400 Series firewalls - PA-7000 Series firewalls</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-3385">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-3384 – A vulnerability in Palo Alto Networks PAN-OS software enables a remote attacker ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-3384</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-3384</guid>
    <pubDate>Wed, 10 Apr 2024 17:15:57 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-3384</strong></p>
  <p>A vulnerability in Palo Alto Networks PAN-OS software enables a remote attacker to reboot PAN-OS firewalls when receiving Windows New Technology LAN Manager (NTLM) packets from Windows servers. Repeated attacks eventually cause the firewall to enter maintenance mode, which requires manual intervention to bring the firewall back online.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-1286</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-3384">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-3383 – A vulnerability in how Palo Alto Networks PAN-OS software processes data receive...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-3383</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-3383</guid>
    <pubDate>Wed, 10 Apr 2024 17:15:57 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-3383</strong></p>
  <p>A vulnerability in how Palo Alto Networks PAN-OS software processes data received from Cloud Identity Engine (CIE) agents enables modification of User-ID groups. This impacts user access to network resources where users may be inappropriately denied or allowed access to resources based on your existing Security Policy rules.</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-282</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-3383">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-3382 – A memory leak exists in Palo Alto Networks PAN-OS software that enables an attac...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-3382</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-3382</guid>
    <pubDate>Wed, 10 Apr 2024 17:15:56 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-3382</strong></p>
  <p>A memory leak exists in Palo Alto Networks PAN-OS software that enables an attacker to send a burst of crafted packets through the firewall that eventually prevents the firewall from processing traffic. This issue applies only to PA-5400 Series devices that are running PAN-OS software with the SSL Forward Proxy feature enabled.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-770</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-3382">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-6790 – A DOM-Based cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-O...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-6790</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-6790</guid>
    <pubDate>Wed, 13 Dec 2023 19:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-6790</strong></p>
  <p>A DOM-Based cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS software enables a remote attacker to execute a JavaScript payload in the context of an administrator’s browser when they view a specifically crafted link to the PAN-OS web interface.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-6790">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-0030 – An authentication bypass vulnerability in the Palo Alto Networks PAN-OS 8.1 web ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-0030</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-0030</guid>
    <pubDate>Wed, 12 Oct 2022 17:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-0030</strong></p>
  <p>An authentication bypass vulnerability in the Palo Alto Networks PAN-OS 8.1 web interface allows a network-based attacker with specific knowledge of the target firewall or Panorama appliance to impersonate an existing PAN-OS administrator and perform privileged actions.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-290</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-0030">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-0024 – A vulnerability exists in Palo Alto Networks PAN-OS software that enables an aut...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-0024</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-0024</guid>
    <pubDate>Wed, 11 May 2022 17:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-0024</strong></p>
  <p>A vulnerability exists in Palo Alto Networks PAN-OS software that enables an authenticated network-based PAN-OS administrator to upload a specifically created configuration that disrupts system processes and potentially execute arbitrary code with root privileges when the configuration is committed on both hardware and virtual firewalls. This issue does not impact Panorama appliances or Prisma Ac…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-138</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-0024">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-3059 – An OS command injection vulnerability in the Palo Alto Networks PAN-OS managemen...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-3059</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-3059</guid>
    <pubDate>Wed, 10 Nov 2021 17:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-3059</strong></p>
  <p>An OS command injection vulnerability in the Palo Alto Networks PAN-OS management interface exists when performing dynamic updates. This vulnerability enables a man-in-the-middle attacker to execute arbitrary OS commands to escalate privileges. This issue impacts: PAN-OS 8.1 versions earlier than PAN-OS 8.1.20-h1; PAN-OS 9.0 versions earlier than PAN-OS 9.0.14-h3; PAN-OS 9.1 versions earlier than…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-3059">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-3058 – An OS command injection vulnerability in the Palo Alto Networks PAN-OS web inter...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-3058</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-3058</guid>
    <pubDate>Wed, 10 Nov 2021 17:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-3058</strong></p>
  <p>An OS command injection vulnerability in the Palo Alto Networks PAN-OS web interface enables an authenticated administrator with permissions to use XML API the ability to execute arbitrary OS commands to escalate privileges. This issue impacts: PAN-OS 8.1 versions earlier than PAN-OS 8.1.20-h1; PAN-OS 9.0 versions earlier than PAN-OS 9.0.14-h3; PAN-OS 9.1 versions earlier than PAN-OS 9.1.11-h2; P…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-3058">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-3056 – A memory corruption vulnerability in Palo Alto Networks PAN-OS GlobalProtect Cli...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-3056</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-3056</guid>
    <pubDate>Wed, 10 Nov 2021 17:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-3056</strong></p>
  <p>A memory corruption vulnerability in Palo Alto Networks PAN-OS GlobalProtect Clientless VPN enables an authenticated attacker to execute arbitrary code with root user privileges during SAML authentication. This issue impacts: PAN-OS 8.1 versions earlier than PAN-OS 8.1.20; PAN-OS 9.0 versions earlier than PAN-OS 9.0.14; PAN-OS 9.1 versions earlier than PAN-OS 9.1.9; PAN-OS 10.0 versions earlier t…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-120</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-3056">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-3054 – A time-of-check to time-of-use (TOCTOU) race condition vulnerability in the Palo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-3054</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-3054</guid>
    <pubDate>Wed, 08 Sep 2021 17:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-3054</strong></p>
  <p>A time-of-check to time-of-use (TOCTOU) race condition vulnerability in the Palo Alto Networks PAN-OS web interface enables an authenticated administrator with permission to upload plugins to execute arbitrary code with root user privileges. This issue impacts: PAN-OS 8.1 versions earlier than PAN-OS 8.1.20; PAN-OS 9.0 versions earlier than PAN-OS 9.0.14; PAN-OS 9.1 versions earlier than PAN-OS 9…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-367</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-3054">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-3053 – An improper handling of exceptional conditions vulnerability exists in the Palo ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-3053</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-3053</guid>
    <pubDate>Wed, 08 Sep 2021 17:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-3053</strong></p>
  <p>An improper handling of exceptional conditions vulnerability exists in the Palo Alto Networks PAN-OS dataplane that enables an unauthenticated network-based attacker to send specifically crafted traffic through the firewall that causes the service to crash. Repeated attempts to send this request result in denial of service to all PAN-OS services by restarting the device and putting it into mainte…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-755</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-3053">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-3050 – An OS command injection vulnerability in the Palo Alto Networks PAN-OS web inter...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-3050</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-3050</guid>
    <pubDate>Wed, 11 Aug 2021 17:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-3050</strong></p>
  <p>An OS command injection vulnerability in the Palo Alto Networks PAN-OS web interface enables an authenticated administrator to execute arbitrary OS commands to escalate privileges. This issue impacts: PAN-OS 9.0 version 9.0.10 through PAN-OS 9.0.14; PAN-OS 9.1 version 9.1.4 through PAN-OS 9.1.10; PAN-OS 10.0 version 10.0.7 and earlier PAN-OS 10.0 versions; PAN-OS 10.1 version 10.1.0 through PAN-O…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-3050">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-2050 – An authentication bypass vulnerability exists in the GlobalProtect SSL VPN compo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-2050</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-2050</guid>
    <pubDate>Thu, 12 Nov 2020 00:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-2050</strong></p>
  <p>An authentication bypass vulnerability exists in the GlobalProtect SSL VPN component of Palo Alto Networks PAN-OS software that allows an attacker to bypass all client certificate checks with an invalid certificate. A remote attacker can successfully authenticate as any user and gain access to restricted VPN network resources when the gateway or portal is configured to rely entirely on certificat…</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-285</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-2050">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-2041 – An insecure configuration of the appweb daemon of Palo Alto Networks PAN-OS 8.1 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-2041</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-2041</guid>
    <pubDate>Wed, 09 Sep 2020 17:15:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-2041</strong></p>
  <p>An insecure configuration of the appweb daemon of Palo Alto Networks PAN-OS 8.1 allows a remote unauthenticated user to send a specifically crafted request to the device that causes the appweb service to crash. Repeated attempts to send this request result in denial of service to all PAN-OS services by restarting the device and putting it into maintenance mode. This issue impacts all versions of…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-16</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-2041">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-2013 – A cleartext transmission of sensitive information vulnerability in Palo Alto Net...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-2013</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-2013</guid>
    <pubDate>Wed, 13 May 2020 19:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-2013</strong></p>
  <p>A cleartext transmission of sensitive information vulnerability in Palo Alto Networks PAN-OS Panorama that discloses an authenticated PAN-OS administrator's PAN-OS session cookie. When an administrator issues a context switch request into a managed firewall with an affected PAN-OS Panorama version, their PAN-OS session cookie is transmitted over cleartext to the firewall. An attacker with the abi…</p>
  <p><strong>CVSS:</strong> 8.3 · <strong>CWE:</strong> CWE-319</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-2013">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-2011 – An improper input validation vulnerability in the configuration daemon of Palo A...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-2011</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-2011</guid>
    <pubDate>Wed, 13 May 2020 19:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-2011</strong></p>
  <p>An improper input validation vulnerability in the configuration daemon of Palo Alto Networks PAN-OS Panorama allows for a remote unauthenticated user to send a specifically crafted registration request to the device that causes the configuration service to crash. Repeated attempts to send this request result in denial of service to all PAN-OS Panorama services by restarting the device and putting…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-2011">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-2009 – An external control of filename vulnerability in the SD WAN component of Palo Al...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-2009</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-2009</guid>
    <pubDate>Wed, 13 May 2020 19:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-2009</strong></p>
  <p>An external control of filename vulnerability in the SD WAN component of Palo Alto Networks PAN-OS Panorama allows an authenticated administrator to send a request that results in the creation and write of an arbitrary file on all firewalls managed by the Panorama. In some cases this results in arbitrary code execution with root permissions. This issue affects: All versions of PAN-OS 7.1; PAN-OS…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-73</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-2009">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-2008 – An OS command injection and external control of filename vulnerability in Palo A...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-2008</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-2008</guid>
    <pubDate>Wed, 13 May 2020 19:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-2008</strong></p>
  <p>An OS command injection and external control of filename vulnerability in Palo Alto Networks PAN-OS allows authenticated administrators to execute code with root privileges or delete arbitrary system files and impact the system's integrity or cause a denial of service condition. This issue affects: All versions of PAN-OS 7.1 and 8.0; PAN-OS 8.1 versions earlier than 8.1.14.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-73</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-2008">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-2002 – An authentication bypass by spoofing vulnerability exists in the authentication ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-2002</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-2002</guid>
    <pubDate>Wed, 13 May 2020 19:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-2002</strong></p>
  <p>An authentication bypass by spoofing vulnerability exists in the authentication daemon and User-ID components of Palo Alto Networks PAN-OS by failing to verify the integrity of the Kerberos key distribution center (KDC) before authenticating users. This affects all forms of authentication that use a Kerberos authentication profile. A man-in-the-middle type of attacker with the ability to intercep…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-290</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-2002">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-2001 – An external control of path and data vulnerability in the Palo Alto Networks PAN...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-2001</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-2001</guid>
    <pubDate>Wed, 13 May 2020 19:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-2001</strong></p>
  <p>An external control of path and data vulnerability in the Palo Alto Networks PAN-OS Panorama XSLT processing logic that allows an unauthenticated user with network access to PAN-OS management interface to write attacker supplied file on the system and elevate privileges. This issue affects: All PAN-OS 7.1 Panorama and 8.0 Panorama versions; PAN-OS 8.1 versions earlier than 8.1.12 on Panorama; PAN…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-123</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-2001">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-1992 – A format string vulnerability in the Varrcvr daemon of PAN-OS on PA-7000 Series ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-1992</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-1992</guid>
    <pubDate>Wed, 08 Apr 2020 19:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-1992</strong></p>
  <p>A format string vulnerability in the Varrcvr daemon of PAN-OS on PA-7000 Series devices with a Log Forwarding Card (LFC) allows remote attackers to crash the daemon creating a denial of service condition or potentially execute code with root privileges. This issue affects Palo Alto Networks PAN-OS 9.0 versions before 9.0.7; PAN-OS 9.1 versions before 9.1.2 on PA-7000 Series devices with an LFC in…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-134</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-1992">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-1990 – A stack-based buffer overflow vulnerability in the management server component o...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-1990</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-1990</guid>
    <pubDate>Wed, 08 Apr 2020 19:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-1990</strong></p>
  <p>A stack-based buffer overflow vulnerability in the management server component of PAN-OS allows an authenticated user to upload a corrupted PAN-OS configuration and potentially execute code with root privileges. This issue affects Palo Alto Networks PAN-OS 8.1 versions before 8.1.13; 9.0 versions before 9.0.7. This issue does not affect PAN-OS 7.1.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-121</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-1990">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-17437 – An improper authentication check in Palo Alto Networks PAN-OS may allow an authe...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-17437</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-17437</guid>
    <pubDate>Thu, 05 Dec 2019 15:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-17437</strong></p>
  <p>An improper authentication check in Palo Alto Networks PAN-OS may allow an authenticated low privileged non-superuser custom role user to elevate privileges and become superuser. This issue affects PAN-OS 7.1 versions prior to 7.1.25; 8.0 versions prior to 8.0.20; 8.1 versions prior to 8.1.11; 9.0 versions prior to 9.0.5. PAN-OS version 7.0 and prior EOL versions have not been evaluated for this…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-280</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-17437">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2017-15944 – Palo Alto Networks PAN-OS before 6.1.19, 7.0.x before 7.0.19, 7.1.x before 7.1.1...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-15944</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-15944</guid>
    <pubDate>Mon, 11 Dec 2017 17:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2017-15944</strong></p>
  <p>Palo Alto Networks PAN-OS before 6.1.19, 7.0.x before 7.0.19, 7.1.x before 7.1.14, and 8.0.x before 8.0.6 allows remote attackers to execute arbitrary code via vectors involving the management interface.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-15944">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-15942 – Palo Alto Networks PAN-OS before 6.1.19, 7.0.x before 7.0.19, 7.1.x before 7.1.1...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-15942</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-15942</guid>
    <pubDate>Mon, 11 Dec 2017 17:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-15942</strong></p>
  <p>Palo Alto Networks PAN-OS before 6.1.19, 7.0.x before 7.0.19, 7.1.x before 7.1.13, and 8.0.x before 8.0.6 allows remote attackers to cause a denial of service via vectors related to the management interface.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-15942">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2017-15940 – The web interface packet capture management component in Palo Alto Networks PAN-...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-15940</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-15940</guid>
    <pubDate>Mon, 11 Dec 2017 17:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2017-15940</strong></p>
  <p>The web interface packet capture management component in Palo Alto Networks PAN-OS before 6.1.19, 7.0.x before 7.0.19, 7.1.x before 7.1.14, and 8.0.x before 8.0.6 allows remote authenticated users to execute arbitrary code via unspecified vectors.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-15940">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2017-9458 – XML external entity (XXE) vulnerability in the GlobalProtect internal and extern...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-9458</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-9458</guid>
    <pubDate>Thu, 07 Sep 2017 13:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2017-9458</strong></p>
  <p>XML external entity (XXE) vulnerability in the GlobalProtect internal and external gateway interface in Palo Alto Networks PAN-OS before 6.1.18, 7.0.x before 7.0.17, 7.1.x before 7.1.12, and 8.0.x before 8.0.3 allows remote attackers to obtain sensitive information, cause a denial of service, or conduct server-side request forgery (SSRF) attacks via unspecified vectors.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-9458">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2017-8390 – The DNS Proxy in Palo Alto Networks PAN-OS before 6.1.18, 7.x before 7.0.16, 7.1...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-8390</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-8390</guid>
    <pubDate>Wed, 02 Aug 2017 19:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2017-8390</strong></p>
  <p>The DNS Proxy in Palo Alto Networks PAN-OS before 6.1.18, 7.x before 7.0.16, 7.1.x before 7.1.11, and 8.x before 8.0.3 allows remote attackers to execute arbitrary code via a crafted domain name.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-8390">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2017-7945 – The GlobalProtect external interface in Palo Alto Networks PAN-OS before 6.1.17,...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-7945</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-7945</guid>
    <pubDate>Sat, 29 Apr 2017 00:59:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2017-7945</strong></p>
  <p>The GlobalProtect external interface in Palo Alto Networks PAN-OS before 6.1.17, 7.x before 7.0.15, 7.1.x before 7.1.9, and 8.x before 8.0.2 provides different error messages for failed login attempts depending on whether the username exists, which allows remote attackers to enumerate account names and conduct brute-force attacks via a series of requests, aka PAN-SA-2017-0014 and PAN-72769.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-209</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-7945">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-7218 – The Management Web Interface in Palo Alto Networks PAN-OS before 7.1.9 allows re...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-7218</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-7218</guid>
    <pubDate>Fri, 14 Apr 2017 14:59:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-7218</strong></p>
  <p>The Management Web Interface in Palo Alto Networks PAN-OS before 7.1.9 allows remote authenticated users to gain privileges via unspecified request parameters.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-7218">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2016-9151 – Palo Alto Networks PAN-OS before 5.0.20, 5.1.x before 5.1.13, 6.0.x before 6.0.1...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-9151</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-9151</guid>
    <pubDate>Sat, 19 Nov 2016 06:59:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2016-9151</strong></p>
  <p>Palo Alto Networks PAN-OS before 5.0.20, 5.1.x before 5.1.13, 6.0.x before 6.0.15, 6.1.x before 6.1.15, 7.0.x before 7.0.11, and 7.1.x before 7.1.6 allows local users to gain privileges via crafted values of unspecified environment variables.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-264</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-9151">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2016-9150 – Buffer overflow in the management web interface in Palo Alto Networks PAN-OS bef...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-9150</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-9150</guid>
    <pubDate>Sat, 19 Nov 2016 06:59:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2016-9150</strong></p>
  <p>Buffer overflow in the management web interface in Palo Alto Networks PAN-OS before 5.0.20, 5.1.x before 5.1.13, 6.0.x before 6.0.15, 6.1.x before 6.1.15, 7.0.x before 7.0.11, and 7.1.x before 7.1.6 allows remote attackers to execute arbitrary code via unspecified vectors.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-9150">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2016-1712 – Palo Alto Networks PAN-OS before 5.0.19, 5.1.x before 5.1.12, 6.0.x before 6.0.1...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-1712</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-1712</guid>
    <pubDate>Tue, 02 Aug 2016 16:59:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2016-1712</strong></p>
  <p>Palo Alto Networks PAN-OS before 5.0.19, 5.1.x before 5.1.12, 6.0.x before 6.0.14, 6.1.x before 6.1.12, and 7.0.x before 7.0.8 might allow local users to gain privileges by leveraging improper sanitization of the root_reboot local invocation.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-1712">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2016-3657 – Buffer overflow in the GlobalProtect Portal in Palo Alto Networks PAN-OS before ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-3657</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-3657</guid>
    <pubDate>Tue, 12 Apr 2016 17:59:05 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2016-3657</strong></p>
  <p>Buffer overflow in the GlobalProtect Portal in Palo Alto Networks PAN-OS before 5.0.18, 6.0.x before 6.0.13, 6.1.x before 6.1.10, and 7.0.x before 7.0.5 allows remote attackers to cause a denial of service (device crash) or possibly execute arbitrary code via an SSL VPN request.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-3657">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2016-3656 – The GlobalProtect Portal in Palo Alto Networks PAN-OS before 5.0.18, 6.0.x befor...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-3656</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-3656</guid>
    <pubDate>Tue, 12 Apr 2016 17:59:05 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2016-3656</strong></p>
  <p>The GlobalProtect Portal in Palo Alto Networks PAN-OS before 5.0.18, 6.0.x before 6.0.13, 6.1.x before 6.1.10, and 7.0.x before 7.0.5H2 allows remote attackers to cause a denial of service (service crash) via a crafted request.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-3656">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2016-3655 – The management web interface in Palo Alto Networks PAN-OS before 5.0.18, 6.0.x b...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-3655</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-3655</guid>
    <pubDate>Tue, 12 Apr 2016 17:59:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2016-3655</strong></p>
  <p>The management web interface in Palo Alto Networks PAN-OS before 5.0.18, 6.0.x before 6.0.13, 6.1.x before 6.1.10, and 7.0.x before 7.0.5 allows remote attackers to execute arbitrary OS commands via an unspecified API call.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-3655">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2016-3654 – The device management command line interface (CLI) in Palo Alto Networks PAN-OS ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-3654</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-3654</guid>
    <pubDate>Tue, 12 Apr 2016 17:59:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2016-3654</strong></p>
  <p>The device management command line interface (CLI) in Palo Alto Networks PAN-OS before 5.0.18, 5.1.x before 5.1.11, 6.0.x before 6.0.13, 6.1.x before 6.1.10, and 7.0.x before 7.0.5H2 allows remote authenticated administrators to execute arbitrary OS commands via an SSH command parameter.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-3654">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2012-6605 – The device-management command-line interface in Palo Alto Networks PAN-OS before...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2012-6605</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2012-6605</guid>
    <pubDate>Sat, 31 Aug 2013 17:55:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2012-6605</strong></p>
  <p>The device-management command-line interface in Palo Alto Networks PAN-OS before 3.1.11 and 4.0.x before 4.0.9 allows remote authenticated users to execute arbitrary code via unspecified vectors, aka Ref ID 34896.</p>
  <p><strong>CVSS:</strong> 9.0 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2012-6605">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2012-6604 – The device-management command-line interface in Palo Alto Networks PAN-OS before...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2012-6604</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2012-6604</guid>
    <pubDate>Sat, 31 Aug 2013 17:55:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2012-6604</strong></p>
  <p>The device-management command-line interface in Palo Alto Networks PAN-OS before 3.1.11 and 4.0.x before 4.0.9 allows remote authenticated users to execute arbitrary code via unspecified vectors, aka Ref ID 35249.</p>
  <p><strong>CVSS:</strong> 9.0 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2012-6604">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2012-6603 – The web management UI in Palo Alto Networks PAN-OS before 3.1.12, 4.0.x before 4...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2012-6603</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2012-6603</guid>
    <pubDate>Sat, 31 Aug 2013 17:55:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2012-6603</strong></p>
  <p>The web management UI in Palo Alto Networks PAN-OS before 3.1.12, 4.0.x before 4.0.10, and 4.1.x before 4.1.4 allows remote attackers to bypass authentication and obtain administrator privileges via unspecified vectors, aka Ref ID 37034.</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2012-6603">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2012-6602 – The device-management command-line interface in Palo Alto Networks PAN-OS before...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2012-6602</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2012-6602</guid>
    <pubDate>Sat, 31 Aug 2013 17:55:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2012-6602</strong></p>
  <p>The device-management command-line interface in Palo Alto Networks PAN-OS before 3.1.10 and 4.0.x before 4.0.4 allows remote authenticated users to execute arbitrary commands via unspecified vectors, aka Ref ID 30122.</p>
  <p><strong>CVSS:</strong> 9.0 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2012-6602">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2012-6601 – The device-management command-line interface in Palo Alto Networks PAN-OS before...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2012-6601</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2012-6601</guid>
    <pubDate>Sat, 31 Aug 2013 17:55:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2012-6601</strong></p>
  <p>The device-management command-line interface in Palo Alto Networks PAN-OS before 3.1.12, 4.0.x before 4.0.10, and 4.1.x before 4.1.4 allows remote attackers to execute arbitrary code via unspecified vectors, aka Ref ID 36983.</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2012-6601">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2012-6600 – The device-management command-line interface in Palo Alto Networks PAN-OS 4.0.x ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2012-6600</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2012-6600</guid>
    <pubDate>Sat, 31 Aug 2013 17:55:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2012-6600</strong></p>
  <p>The device-management command-line interface in Palo Alto Networks PAN-OS 4.0.x before 4.0.9 and 4.1.x before 4.1.2 allows remote authenticated users to execute arbitrary commands via unspecified vectors, aka Ref ID 34502.</p>
  <p><strong>CVSS:</strong> 9.0 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2012-6600">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2012-6599 – The device-management command-line interface in Palo Alto Networks PAN-OS 4.0.x ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2012-6599</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2012-6599</guid>
    <pubDate>Sat, 31 Aug 2013 17:55:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2012-6599</strong></p>
  <p>The device-management command-line interface in Palo Alto Networks PAN-OS 4.0.x before 4.0.8 and 4.1.x before 4.1.1 allows remote authenticated users to execute arbitrary commands via unspecified vectors, aka Ref ID 33476.</p>
  <p><strong>CVSS:</strong> 9.0 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2012-6599">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2012-6598 – The device-management command-line interface in Palo Alto Networks PAN-OS 4.0.x ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2012-6598</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2012-6598</guid>
    <pubDate>Sat, 31 Aug 2013 17:55:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2012-6598</strong></p>
  <p>The device-management command-line interface in Palo Alto Networks PAN-OS 4.0.x before 4.0.8 allows remote authenticated users to execute arbitrary commands via unspecified vectors, aka Ref ID 33080.</p>
  <p><strong>CVSS:</strong> 9.0 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2012-6598">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2012-6595 – The device-management command-line interface in Palo Alto Networks PAN-OS 4.0.x ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2012-6595</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2012-6595</guid>
    <pubDate>Sat, 31 Aug 2013 17:55:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2012-6595</strong></p>
  <p>The device-management command-line interface in Palo Alto Networks PAN-OS 4.0.x before 4.0.9 and 4.1.x before 4.1.2 allows remote authenticated administrators to execute arbitrary commands via unspecified vectors, aka Ref ID 34595.</p>
  <p><strong>CVSS:</strong> 9.0 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2012-6595">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2012-6594 – The device-management command-line interface in Palo Alto Networks PAN-OS before...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2012-6594</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2012-6594</guid>
    <pubDate>Sat, 31 Aug 2013 17:55:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2012-6594</strong></p>
  <p>The device-management command-line interface in Palo Alto Networks PAN-OS before 3.1.11, 4.0.x before 4.0.8, and 4.1.x before 4.1.1 allows remote authenticated administrators to execute arbitrary commands via unspecified vectors, aka Ref ID 34299.</p>
  <p><strong>CVSS:</strong> 9.0 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2012-6594">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2012-6593 – Palo Alto Networks PAN-OS before 3.1.10 and 4.0.x before 4.0.4 allows remote att...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2012-6593</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2012-6593</guid>
    <pubDate>Sat, 31 Aug 2013 17:55:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2012-6593</strong></p>
  <p>Palo Alto Networks PAN-OS before 3.1.10 and 4.0.x before 4.0.4 allows remote attackers to execute arbitrary commands via unspecified vectors, aka Ref ID 30088.</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2012-6593">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2012-6592 – Palo Alto Networks PAN-OS before 3.1.10 and 4.0.x before 4.0.5 allows remote att...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2012-6592</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2012-6592</guid>
    <pubDate>Sat, 31 Aug 2013 17:55:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2012-6592</strong></p>
  <p>Palo Alto Networks PAN-OS before 3.1.10 and 4.0.x before 4.0.5 allows remote attackers to execute arbitrary commands via unspecified vectors, aka Ref ID 31091.</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2012-6592">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2012-6591 – The device-management command-line interface in Palo Alto Networks PAN-OS before...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2012-6591</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2012-6591</guid>
    <pubDate>Sat, 31 Aug 2013 17:55:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2012-6591</strong></p>
  <p>The device-management command-line interface in Palo Alto Networks PAN-OS before 3.1.10 and 4.0.x before 4.0.5 allows remote authenticated administrators to execute arbitrary commands via unspecified vectors, aka Ref ID 31116.</p>
  <p><strong>CVSS:</strong> 9.0 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2012-6591">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
