<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Palo Alto Networks PAN-OS</title>
  <link>https://cvedaily.com/pages/tags/panos.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/panos.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Palo Alto Networks PAN-OS</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:48 +0000</lastBuildDate>
  <item>
    <title>[Medium] CVE-2026-0262 – Multiple denial of service vulnerabilities in Palo Alto Networks PAN-OS® softwar...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-0262</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-0262</guid>
    <pubDate>Wed, 13 May 2026 19:17:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-0262</strong></p>
  <p>Multiple denial of service vulnerabilities in Palo Alto Networks PAN-OS® software allow an unauthenticated attacker with network access to cause a denial of service (DoS) condition by sending specially crafted network traffic.   Panorama and Cloud NGFW are not impacted by these vulnerabilities.</p>
  <p><strong>CVSS:</strong> 6.6 · <strong>CWE:</strong> CWE-754</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-0262">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-0261 – Multiple command injection vulnerabilities in Palo Alto Networks PAN-OS® softwar...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-0261</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-0261</guid>
    <pubDate>Wed, 13 May 2026 19:17:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-0261</strong></p>
  <p>Multiple command injection vulnerabilities in Palo Alto Networks PAN-OS® software enable an authenticated administrator to bypass system restrictions and run arbitrary commands as a root user. To be able to exploit this issue, the user must have access to the PAN-OS CLI or Web UI.    The security risk posed by this issue is significantly minimized when CLI access is restricted to a limited group…</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-0261">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-0258 – A server-side request forgery (SSRF) vulnerability in the IKEv2 implementation o...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-0258</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-0258</guid>
    <pubDate>Wed, 13 May 2026 19:17:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-0258</strong></p>
  <p>A server-side request forgery (SSRF) vulnerability in the IKEv2 implementation of Palo Alto Networks PAN-OS® software allows an unauthenticated attacker to cause the firewall to send network requests to unintended destinations or cause a denial of service (DoS) condition.    Panorama, Cloud NGFW and Prisma® Access are not impacted by these vulnerabilities.</p>
  <p><strong>CVSS:</strong> 4.8 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-0258">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-0257 – Authentication bypass vulnerabilities in the GlobalProtect portal and gateway of...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-0257</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-0257</guid>
    <pubDate>Wed, 13 May 2026 19:17:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-0257</strong></p>
  <p>Authentication bypass vulnerabilities in the GlobalProtect portal and gateway of Palo Alto Networks PAN-OS® software allows the attacker to bypass security restrictions and establish an unauthorized VPN connection.  Panorama and Cloud NGFW are not impacted by these issues.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-565</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-0257">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-0256 – A stored cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS® ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-0256</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-0256</guid>
    <pubDate>Wed, 13 May 2026 19:17:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-0256</strong></p>
  <p>A stored cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS® software enables a malicious authenticated administrator to store a JavaScript payload using the web interface.   This issue is applicable to PAN-OS software on PA-Series and VM-Series firewalls and on Panorama (virtual and M-Series).  Cloud NGFW and Prisma® Access are not impacted by this vulnerability.</p>
  <p><strong>CVSS:</strong> 4.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-0256">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-0265 – An authentication bypass vulnerability in Palo Alto Networks PAN-OS® software en...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-0265</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-0265</guid>
    <pubDate>Wed, 13 May 2026 18:16:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-0265</strong></p>
  <p>An authentication bypass vulnerability in Palo Alto Networks PAN-OS® software enables an unauthenticated attacker with network access to bypass authentication controls when Cloud Authentication Service (CAS) is enabled.    The risk is higher if CAS is enabled on the management interface and lower when any other login interfaces are used.  The risk of this issue is greatly reduced if you secure ac…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-347</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-0265">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-0264 – A buffer overflow vulnerability in the DNS proxy and DNS Server features of Palo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-0264</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-0264</guid>
    <pubDate>Wed, 13 May 2026 18:16:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-0264</strong></p>
  <p>A buffer overflow vulnerability in the DNS proxy and DNS Server features of Palo Alto Networks PAN-OS® Software allows an unauthenticated attacker with network access to cause a denial of service (DoS) condition (all PAN-OS platforms except Cloud NGFW and Prisma Access) or potentially execute arbitrary code by sending specially crafted network traffic (PA-Series hardware only).     Panorama, Clou…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-122</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-0264">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-0263 – A buffer overflow vulnerability in the IKEv2 processing of Palo Alto Networks PA...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-0263</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-0263</guid>
    <pubDate>Wed, 13 May 2026 18:16:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-0263</strong></p>
  <p>A buffer overflow vulnerability in the IKEv2 processing of Palo Alto Networks PAN-OS® software allows an unauthenticated network-based attacker to execute arbitrary code with elevated privileges on the firewall, or cause a denial of service (DoS) condition.   Panorama, Cloud NGFW, and Prisma® Access are not impacted by these vulnerabilities.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-0263">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-0300 – A buffer overflow vulnerability in the User-ID™ Authentication Portal (aka Capti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-0300</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-0300</guid>
    <pubDate>Wed, 06 May 2026 19:16:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-0300</strong></p>
  <p>A buffer overflow vulnerability in the User-ID™ Authentication Portal (aka Captive Portal) service of Palo Alto Networks PAN-OS software allows an unauthenticated attacker to execute arbitrary code with root privileges on the PA-Series and VM-Series firewalls by sending specially crafted packets.   The risk of this issue is greatly reduced if you secure access to the User-ID™ Authentication Porta…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-0300">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-0229 – A denial-of-service (DoS) vulnerability in the Advanced DNS Security (ADNS) feat...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-0229</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-0229</guid>
    <pubDate>Wed, 11 Feb 2026 18:16:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-0229</strong></p>
  <p>A denial-of-service (DoS) vulnerability in the Advanced DNS Security (ADNS) feature of Palo Alto Networks PAN-OS® software enables an unauthenticated attacker to initiate system reboots using a maliciously crafted packet. Repeated attempts to initiate a reboot causes the firewall to enter maintenance mode.  Cloud NGFW and Prisma Access® are not impacted by this vulnerability.</p>
  <p><strong>CVSS:</strong> 6.6 · <strong>CWE:</strong> CWE-754</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-0229">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-0227 – A vulnerability in Palo Alto Networks PAN-OS software enables an unauthenticated...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-0227</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-0227</guid>
    <pubDate>Thu, 15 Jan 2026 19:16:05 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-0227</strong></p>
  <p>A vulnerability in Palo Alto Networks PAN-OS software enables an unauthenticated attacker to cause a denial of service (DoS) to the firewall. Repeated attempts to trigger this issue results in the firewall entering into maintenance mode.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-754</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-0227">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-4619 – A denial-of-service (DoS) vulnerability in Palo Alto Networks PAN-OS software en...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-4619</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-4619</guid>
    <pubDate>Thu, 13 Nov 2025 21:15:49 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-4619</strong></p>
  <p>A denial-of-service (DoS) vulnerability in Palo Alto Networks PAN-OS software enables an unauthenticated attacker to reboot a firewall by sending a specially crafted packet through the dataplane. Repeated attempts to initiate a reboot causes the firewall to enter maintenance mode.  This issue is applicable to the PAN-OS software versions listed below on PA-Series firewalls, VM-Series firewalls, a…</p>
  <p><strong>CVSS:</strong> 6.6 · <strong>CWE:</strong> CWE-754</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-4619">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-4615 – An improper input neutralization vulnerability in the management web interface o...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-4615</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-4615</guid>
    <pubDate>Thu, 09 Oct 2025 19:15:43 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-4615</strong></p>
  <p>An improper input neutralization vulnerability in the management web interface of the Palo Alto Networks PAN-OS® software enables an authenticated administrator to bypass system restrictions and execute arbitrary commands.  The security risk posed by this issue is significantly minimized when CLI access is restricted to a limited group of administrators.  Cloud NGFW and Prisma® Access are not aff…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-83</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-4615">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2025-4614 – An information disclosure vulnerability in Palo Alto Networks PAN-OS® software e...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-4614</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-4614</guid>
    <pubDate>Thu, 09 Oct 2025 19:15:43 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2025-4614</strong></p>
  <p>An information disclosure vulnerability in Palo Alto Networks PAN-OS® software enables an authenticated administrator to view session tokens of users authenticated to the firewall web UI. This may allow impersonation of users whose session tokens are leaked.    The security risk posed by this issue is significantly minimized when CLI access is restricted to a limited group of administrators.  Clo…</p>
  <p><strong>CVSS:</strong> 2.7 · <strong>CWE:</strong> CWE-497</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-4614">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-2182 – A problem with the implementation of the MACsec protocol in Palo Alto Networks P...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-2182</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-2182</guid>
    <pubDate>Wed, 13 Aug 2025 17:15:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-2182</strong></p>
  <p>A problem with the implementation of the MACsec protocol in Palo Alto Networks PAN-OS® results in the cleartext exposure of the connectivity association key (CAK). This issue is only applicable to PA-7500 Series devices which are in an NGFW cluster. A user who possesses this key can read messages being sent between devices in a NGFW Cluster. There is no impact in non-clustered firewalls or cluste…</p>
  <p><strong>CVSS:</strong> 5.6 · <strong>CWE:</strong> CWE-312</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-2182">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-4229 – An information disclosure vulnerability in the SD-WAN feature of Palo Alto Netwo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-4229</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-4229</guid>
    <pubDate>Fri, 13 Jun 2025 06:15:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-4229</strong></p>
  <p>An information disclosure vulnerability in the SD-WAN feature of Palo Alto Networks PAN-OS® software enables an unauthorized user to view unencrypted data sent from the firewall through the SD-WAN interface. This requires the user to be able to intercept packets sent from the firewall.  Cloud NGFW and Prisma® Access are not affected by this vulnerability.</p>
  <p><strong>CVSS:</strong> 6.0 · <strong>CWE:</strong> CWE-497</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-4229">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-4231 – A command injection vulnerability in Palo Alto Networks PAN-OS® enables an authe...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-4231</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-4231</guid>
    <pubDate>Fri, 13 Jun 2025 00:15:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-4231</strong></p>
  <p>A command injection vulnerability in Palo Alto Networks PAN-OS® enables an authenticated administrative user to perform actions as the root user.  The attacker must have network access to the management web interface and successfully authenticate to exploit this issue.  Cloud NGFW and Prisma Access are not impacted by this vulnerability.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-4231">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-4230 – A command injection vulnerability in Palo Alto Networks PAN-OS® software enables...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-4230</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-4230</guid>
    <pubDate>Fri, 13 Jun 2025 00:15:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-4230</strong></p>
  <p>A command injection vulnerability in Palo Alto Networks PAN-OS® software enables an authenticated administrator to bypass system restrictions and run arbitrary commands as a root user. To be able to exploit this issue, the user must have access to the PAN-OS CLI.  The security risk posed by this issue is significantly minimized when CLI access is restricted to a limited group of administrators.…</p>
  <p><strong>CVSS:</strong> 8.4 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-4230">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-0137 – An improper input neutralization vulnerability in the management web interface o...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-0137</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-0137</guid>
    <pubDate>Wed, 14 May 2025 19:15:52 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-0137</strong></p>
  <p>An improper input neutralization vulnerability in the management web interface of the Palo Alto Networks PAN-OS® software enables a malicious authenticated read-write administrator to impersonate another legitimate authenticated PAN-OS administrator.   The attacker must have network access to the management web interface to exploit this issue. You greatly reduce the risk of this issue by restrict…</p>
  <p><strong>CVSS:</strong> 4.8 · <strong>CWE:</strong> CWE-83</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-0137">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-0136 – Using the AES-128-CCM algorithm for IPSec on certain Palo Alto Networks PAN-OS® ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-0136</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-0136</guid>
    <pubDate>Wed, 14 May 2025 19:15:51 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-0136</strong></p>
  <p>Using the AES-128-CCM algorithm for IPSec on certain Palo Alto Networks PAN-OS® firewalls (PA-7500, PA-5400, PA-5400f, PA-3400, PA-1600, PA-1400, and PA-400 Series) leads to unencrypted data transfer to devices that are connected to the PAN-OS firewall through IPSec.  This issue does not affect Cloud NGFWs, Prisma® Access instances, or  PAN-OS VM-Series firewalls.  NOTE: The AES-128-CCM encryptio…</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-319</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-0136">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2025-0133 – A reflected cross-site scripting (XSS) vulnerability in the GlobalProtect™ gatew...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-0133</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-0133</guid>
    <pubDate>Wed, 14 May 2025 19:15:51 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2025-0133</strong></p>
  <p>A reflected cross-site scripting (XSS) vulnerability in the GlobalProtect™ gateway and portal features of Palo Alto Networks PAN-OS® software enables execution of malicious JavaScript in the context of an authenticated Captive Portal user's browser when they click on a specially crafted link. The primary risk is phishing attacks that can lead to credential theft—particularly if you enabled Client…</p>
  <p><strong>CVSS:</strong> 2.7 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-0133">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-0130 – A missing exception check in Palo Alto Networks PAN-OS® software with the web pr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-0130</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-0130</guid>
    <pubDate>Wed, 14 May 2025 18:15:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-0130</strong></p>
  <p>A missing exception check in Palo Alto Networks PAN-OS® software with the web proxy feature enabled allows an unauthenticated attacker to send a burst of maliciously crafted packets that causes the firewall to become unresponsive and eventually reboot. Repeated successful attempts to trigger this condition will cause the firewall to enter maintenance mode.    This issue does not affect Cloud NGFW…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-754</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-0130">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-0123 – A vulnerability in the Palo Alto Networks PAN-OS® software enables unlicensed ad...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-0123</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-0123</guid>
    <pubDate>Fri, 11 Apr 2025 18:15:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-0123</strong></p>
  <p>A vulnerability in the Palo Alto Networks PAN-OS® software enables unlicensed administrators to view clear-text data captured using the  packet capture feature https://docs.paloaltonetworks.com/pan-os/11-0/pan-os-admin/monitoring/take-packet-captures/take-a-custom-packet-capture  in decrypted HTTP/2 data streams traversing network interfaces on the firewall. HTTP/1.1 data streams are not impacted…</p>
  <p><strong>CVSS:</strong> 5.9 · <strong>CWE:</strong> CWE-312</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-0123">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-0128 – A denial-of-service (DoS) vulnerability in the Simple Certificate Enrollment Pro...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-0128</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-0128</guid>
    <pubDate>Fri, 11 Apr 2025 02:15:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-0128</strong></p>
  <p>A denial-of-service (DoS) vulnerability in the Simple Certificate Enrollment Protocol (SCEP) authentication feature of Palo Alto Networks PAN-OS® software enables an unauthenticated attacker to initiate system reboots using a maliciously crafted packet. Repeated attempts to initiate a reboot causes the firewall to enter maintenance mode.  Cloud NGFW is not affected by this vulnerability. Prisma®…</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-754</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-0128">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-0127 – A command injection vulnerability in Palo Alto Networks PAN-OS® software enables...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-0127</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-0127</guid>
    <pubDate>Fri, 11 Apr 2025 02:15:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-0127</strong></p>
  <p>A command injection vulnerability in Palo Alto Networks PAN-OS® software enables an authenticated administrator to bypass system restrictions and run arbitrary commands as a root user. This issue is only applicable to PAN-OS VM-Series. This issue does not affect firewalls that are already deployed.  Cloud NGFW and Prisma® Access are not affected by this vulnerability.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-0127">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-0125 – An improper input neutralization vulnerability in the management web interface o...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-0125</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-0125</guid>
    <pubDate>Fri, 11 Apr 2025 02:15:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-0125</strong></p>
  <p>An improper input neutralization vulnerability in the management web interface of the Palo Alto Networks PAN-OS® software enables a malicious authenticated read-write administrator to impersonate another legitimate authenticated PAN-OS administrator.   The attacker must have network access to the management web interface to exploit this issue. You greatly reduce the risk of this issue by restrict…</p>
  <p><strong>CVSS:</strong> 6.9 · <strong>CWE:</strong> CWE-83</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-0125">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2025-0124 – An authenticated file deletion vulnerability in the Palo Alto Networks PAN-OS® s...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-0124</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-0124</guid>
    <pubDate>Fri, 11 Apr 2025 02:15:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2025-0124</strong></p>
  <p>An authenticated file deletion vulnerability in the Palo Alto Networks PAN-OS® software enables an authenticated attacker with network access to the management web interface to delete certain files as the “nobody” user; this includes limited logs and configuration files but does not include system files.  The attacker must have network access to the management web interface to exploit this issue.…</p>
  <p><strong>CVSS:</strong> 3.8 · <strong>CWE:</strong> CWE-73</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-0124">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-0116 – A Denial of Service (DoS) vulnerability in Palo Alto Networks PAN-OS software ca...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-0116</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-0116</guid>
    <pubDate>Wed, 12 Mar 2025 19:15:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-0116</strong></p>
  <p>A Denial of Service (DoS) vulnerability in Palo Alto Networks PAN-OS software causes the firewall to unexpectedly reboot when processing a specially crafted LLDP frame sent by an unauthenticated adjacent attacker. Repeated attempts to initiate this condition causes the firewall to enter maintenance mode.  This issue does not apply to Cloud NGFWs or Prisma Access software.</p>
  <p><strong>CVSS:</strong> 6.8 · <strong>CWE:</strong> CWE-754</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-0116">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-0115 – A vulnerability in the Palo Alto Networks PAN-OS software enables an authenticat...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-0115</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-0115</guid>
    <pubDate>Wed, 12 Mar 2025 19:15:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-0115</strong></p>
  <p>A vulnerability in the Palo Alto Networks PAN-OS software enables an authenticated admin on the PAN-OS CLI to read arbitrary files.  The attacker must have network access to the management interface (web, SSH, console, or telnet) and successfully authenticate to exploit this issue. You can greatly reduce the risk of this issue by restricting access to the management interface to only trusted user…</p>
  <p><strong>CVSS:</strong> 6.8 · <strong>CWE:</strong> CWE-41</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-0115">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-0114 – A Denial of Service (DoS) vulnerability in the GlobalProtect feature of Palo Alt...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-0114</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-0114</guid>
    <pubDate>Wed, 12 Mar 2025 19:15:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-0114</strong></p>
  <p>A Denial of Service (DoS) vulnerability in the GlobalProtect feature of Palo Alto Networks PAN-OS software enables an unauthenticated attacker to render the service unavailable by sending a large number of specially crafted packets over a period of time. This issue affects both the GlobalProtect portal and the GlobalProtect gateway.  This issue does not apply to Cloud NGFWs or Prisma Access softw…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-0114">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-0111 – An authenticated file read vulnerability in the Palo Alto Networks PAN-OS softwa...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-0111</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-0111</guid>
    <pubDate>Wed, 12 Feb 2025 21:15:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-0111</strong></p>
  <p>An authenticated file read vulnerability in the Palo Alto Networks PAN-OS software enables an authenticated attacker with network access to the management web interface to read files on the PAN-OS filesystem that are readable by the “nobody” user.  You can greatly reduce the risk of this issue by restricting access to the management web interface to only trusted internal IP addresses according to…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-73</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-0111">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-0110 – A command injection vulnerability in the Palo Alto Networks PAN-OS OpenConfig pl...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-0110</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-0110</guid>
    <pubDate>Wed, 12 Feb 2025 21:15:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-0110</strong></p>
  <p>A command injection vulnerability in the Palo Alto Networks PAN-OS OpenConfig plugin enables an authenticated administrator with the ability to make gNMI requests to the PAN-OS management web interface to bypass system restrictions and run arbitrary commands. The commands are run as the “__openconfig” user (which has the Device Administrator role) on the firewall.  You can greatly reduce the risk…</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-0110">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-0109 – An unauthenticated file deletion vulnerability in the Palo Alto Networks PAN-OS ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-0109</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-0109</guid>
    <pubDate>Wed, 12 Feb 2025 21:15:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-0109</strong></p>
  <p>An unauthenticated file deletion vulnerability in the Palo Alto Networks PAN-OS management web interface enables an unauthenticated attacker with network access to the management web interface to delete certain files as the “nobody” user; this includes limited logs and configuration files but does not include system files.   You can greatly reduce the risk of this issue by restricting access to t…</p>
  <p><strong>CVSS:</strong> 6.9 · <strong>CWE:</strong> CWE-73</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-0109">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-0108 – An authentication bypass in the Palo Alto Networks PAN-OS software enables an un...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-0108</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-0108</guid>
    <pubDate>Wed, 12 Feb 2025 21:15:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-0108</strong></p>
  <p>An authentication bypass in the Palo Alto Networks PAN-OS software enables an unauthenticated attacker with network access to the management web interface to bypass the authentication otherwise required by the PAN-OS management web interface and invoke certain PHP scripts. While invoking these PHP scripts does not enable remote code execution, it can negatively impact integrity and confidentialit…</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-306</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-0108">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-3393 – A Denial of Service vulnerability in the DNS Security feature of Palo Alto Netwo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-3393</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-3393</guid>
    <pubDate>Fri, 27 Dec 2024 10:15:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-3393</strong></p>
  <p>A Denial of Service vulnerability in the DNS Security feature of Palo Alto Networks PAN-OS software allows an unauthenticated attacker to send a malicious packet through the data plane of the firewall that reboots the firewall. Repeated attempts to trigger this condition will cause the firewall to enter maintenance mode.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-754</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-3393">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-9474 – A privilege escalation vulnerability in Palo Alto Networks PAN-OS software allow...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-9474</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-9474</guid>
    <pubDate>Mon, 18 Nov 2024 16:15:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-9474</strong></p>
  <p>A privilege escalation vulnerability in Palo Alto Networks PAN-OS software allows a PAN-OS administrator with access to the management web interface to perform actions on the firewall with root privileges.  Cloud NGFW and Prisma Access are not impacted by this vulnerability.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-9474">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-0012 – An authentication bypass in Palo Alto Networks PAN-OS software enables an unauth...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-0012</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-0012</guid>
    <pubDate>Mon, 18 Nov 2024 16:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-0012</strong></p>
  <p>An authentication bypass in Palo Alto Networks PAN-OS software enables an unauthenticated attacker with network access to the management web interface to gain PAN-OS administrator privileges to perform administrative actions, tamper with the configuration, or exploit other authenticated privilege escalation vulnerabilities like  CVE-2024-9474 https://security.paloaltonetworks.com/CVE-2024-9474 .…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-306</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-0012">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-9472 – A null pointer dereference in Palo Alto Networks PAN-OS software on PA-800 Serie...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-9472</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-9472</guid>
    <pubDate>Thu, 14 Nov 2024 10:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-9472</strong></p>
  <p>A null pointer dereference in Palo Alto Networks PAN-OS software on PA-800 Series, PA-3200 Series, PA-5200 Series, and PA-7000 Series hardware platforms when Decryption policy is enabled allows an unauthenticated attacker to crash PAN-OS by sending specific traffic through the data plane, resulting in a denial of service (DoS) condition. Repeated attempts to trigger this condition will result in…</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-9472">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-5920 – A cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS software...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-5920</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-5920</guid>
    <pubDate>Thu, 14 Nov 2024 10:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-5920</strong></p>
  <p>A cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS software enables an authenticated read-write Panorama administrator to push a specially crafted configuration to a PAN-OS node. This enables impersonation of a legitimate PAN-OS administrator who can perform restricted actions on the PAN-OS node after the execution of JavaScript in the legitimate PAN-OS administrator's browse…</p>
  <p><strong>CVSS:</strong> 4.8 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-5920">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-5919 – A blind XML External Entities (XXE) injection vulnerability in the Palo Alto Net...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-5919</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-5919</guid>
    <pubDate>Thu, 14 Nov 2024 10:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-5919</strong></p>
  <p>A blind XML External Entities (XXE) injection vulnerability in the Palo Alto Networks PAN-OS software enables an authenticated attacker to exfiltrate arbitrary files from firewalls to an attacker controlled server. This attack requires network access to the firewall management interface.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-5919">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-5918 – An improper certificate validation vulnerability in Palo Alto Networks PAN-OS so...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-5918</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-5918</guid>
    <pubDate>Thu, 14 Nov 2024 10:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-5918</strong></p>
  <p>An improper certificate validation vulnerability in Palo Alto Networks PAN-OS software enables an authorized user with a specially crafted client certificate to connect to an impacted GlobalProtect portal or GlobalProtect gateway as a different legitimate user. This attack is possible only if you "Allow Authentication with User Credentials OR Client Certificate."</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-5918">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-2552 – A command injection vulnerability in Palo Alto Networks PAN-OS software enables ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-2552</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-2552</guid>
    <pubDate>Thu, 14 Nov 2024 10:15:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-2552</strong></p>
  <p>A command injection vulnerability in Palo Alto Networks PAN-OS software enables an authenticated administrator to bypass system restrictions in the management plane and delete files on the firewall.</p>
  <p><strong>CVSS:</strong> 6.0 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-2552">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-2551 – A null pointer dereference vulnerability in Palo Alto Networks PAN-OS software e...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-2551</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-2551</guid>
    <pubDate>Thu, 14 Nov 2024 10:15:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-2551</strong></p>
  <p>A null pointer dereference vulnerability in Palo Alto Networks PAN-OS software enables an unauthenticated attacker to stop a core system service on the firewall by sending a crafted packet through the data plane that causes a denial of service (DoS) condition. Repeated attempts to trigger this condition result in the firewall entering maintenance mode.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-2551">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-2550 – A null pointer dereference vulnerability in the GlobalProtect gateway in Palo Al...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-2550</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-2550</guid>
    <pubDate>Thu, 14 Nov 2024 10:15:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-2550</strong></p>
  <p>A null pointer dereference vulnerability in the GlobalProtect gateway in Palo Alto Networks PAN-OS software enables an unauthenticated attacker to stop the GlobalProtect service on the firewall by sending a specially crafted packet that causes a denial of service (DoS) condition. Repeated attempts to trigger this condition result in the firewall entering maintenance mode.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-2550">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-9471 – A privilege escalation (PE) vulnerability in the XML API of Palo Alto Networks P...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-9471</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-9471</guid>
    <pubDate>Wed, 09 Oct 2024 17:15:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-9471</strong></p>
  <p>A privilege escalation (PE) vulnerability in the XML API of Palo Alto Networks PAN-OS software enables an authenticated PAN-OS administrator with restricted privileges to use a compromised XML API key to perform actions as a higher privileged PAN-OS administrator. For example, an administrator with "Virtual system administrator (read-only)" access could use an XML API key of a "Virtual system adm…</p>
  <p><strong>CVSS:</strong> 4.7 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-9471">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-9468 – A memory corruption vulnerability in Palo Alto Networks PAN-OS software allows a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-9468</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-9468</guid>
    <pubDate>Wed, 09 Oct 2024 17:15:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-9468</strong></p>
  <p>A memory corruption vulnerability in Palo Alto Networks PAN-OS software allows an unauthenticated attacker to crash PAN-OS due to a crafted packet through the data plane, resulting in a denial of service (DoS) condition. Repeated attempts to trigger this condition will result in PAN-OS entering maintenance mode.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-9468">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-8691 – A vulnerability in the GlobalProtect portal in Palo Alto Networks PAN-OS softwar...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-8691</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-8691</guid>
    <pubDate>Wed, 11 Sep 2024 17:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-8691</strong></p>
  <p>A vulnerability in the GlobalProtect portal in Palo Alto Networks PAN-OS software enables a malicious authenticated GlobalProtect user to impersonate another GlobalProtect user. Active GlobalProtect users impersonated by an attacker who is exploiting this vulnerability are disconnected from GlobalProtect. Upon exploitation, PAN-OS logs indicate that the impersonated user authenticated to GlobalPr…</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-8691">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-8688 – An improper neutralization of matching symbols vulnerability in the Palo Alto Ne...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-8688</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-8688</guid>
    <pubDate>Wed, 11 Sep 2024 17:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-8688</strong></p>
  <p>An improper neutralization of matching symbols vulnerability in the Palo Alto Networks PAN-OS command line interface (CLI) enables authenticated administrators (including read-only administrators) with access to the CLI to to read arbitrary files on the firewall.</p>
  <p><strong>CVSS:</strong> 4.4 · <strong>CWE:</strong> CWE-155</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-8688">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-8687 – An information exposure vulnerability exists in Palo Alto Networks PAN-OS softwa...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-8687</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-8687</guid>
    <pubDate>Wed, 11 Sep 2024 17:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-8687</strong></p>
  <p>An information exposure vulnerability exists in Palo Alto Networks PAN-OS software that enables a GlobalProtect end user to learn both the configured GlobalProtect uninstall password and the configured disable or disconnect passcode. After the password or passcode is known, end users can uninstall, disable, or disconnect GlobalProtect even if the GlobalProtect app configuration would not normally…</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-497</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-8687">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-8686 – A command injection vulnerability in Palo Alto Networks PAN-OS software enables ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-8686</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-8686</guid>
    <pubDate>Wed, 11 Sep 2024 17:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-8686</strong></p>
  <p>A command injection vulnerability in Palo Alto Networks PAN-OS software enables an authenticated administrator to bypass system restrictions and run arbitrary commands as root on the firewall.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-8686">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-5916 – An information exposure vulnerability in Palo Alto Networks PAN-OS software enab...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-5916</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-5916</guid>
    <pubDate>Wed, 14 Aug 2024 17:15:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-5916</strong></p>
  <p>An information exposure vulnerability in Palo Alto Networks PAN-OS software enables a local system administrator to unintentionally disclose secrets, passwords, and tokens of external systems. A read-only administrator who has access to the config log, can read secrets, passwords, and tokens to external systems.</p>
  <p><strong>CVSS:</strong> 4.4 · <strong>CWE:</strong> CWE-313</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-5916">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-5913 – An improper input validation vulnerability in Palo Alto Networks PAN-OS software...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-5913</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-5913</guid>
    <pubDate>Wed, 10 Jul 2024 19:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-5913</strong></p>
  <p>An improper input validation vulnerability in Palo Alto Networks PAN-OS software enables an attacker with the ability to tamper with the physical file system to elevate privileges.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-5913">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-3400 – A command injection as a result of arbitrary file creation vulnerability in the ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-3400</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-3400</guid>
    <pubDate>Fri, 12 Apr 2024 08:15:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-3400</strong></p>
  <p>A command injection as a result of arbitrary file creation vulnerability in the GlobalProtect feature of Palo Alto Networks PAN-OS software for specific PAN-OS versions and distinct feature configurations may enable an unauthenticated attacker to execute arbitrary code with root privileges on the firewall.  Cloud NGFW, Panorama appliances, and Prisma Access are not impacted by this vulnerability.</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-3400">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-3388 – A vulnerability in the GlobalProtect Gateway in Palo Alto Networks PAN-OS softwa...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-3388</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-3388</guid>
    <pubDate>Wed, 10 Apr 2024 17:15:57 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-3388</strong></p>
  <p>A vulnerability in the GlobalProtect Gateway in Palo Alto Networks PAN-OS software enables an authenticated attacker to impersonate another user and send network packets to internal assets. However, this vulnerability does not allow the attacker to receive response packets from those internal assets.</p>
  <p><strong>CVSS:</strong> 4.1 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-3388">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-3386 – An incorrect string comparison vulnerability in Palo Alto Networks PAN-OS softwa...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-3386</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-3386</guid>
    <pubDate>Wed, 10 Apr 2024 17:15:57 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-3386</strong></p>
  <p>An incorrect string comparison vulnerability in Palo Alto Networks PAN-OS software prevents Predefined Decryption Exclusions from functioning as intended. This can cause traffic destined for domains that are not specified in Predefined Decryption Exclusions to be unintentionally excluded from decryption.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-436</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-3386">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-3385 – A packet processing mechanism in Palo Alto Networks PAN-OS software enables a re...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-3385</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-3385</guid>
    <pubDate>Wed, 10 Apr 2024 17:15:57 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-3385</strong></p>
  <p>A packet processing mechanism in Palo Alto Networks PAN-OS software enables a remote attacker to reboot hardware-based firewalls. Repeated attacks eventually cause the firewall to enter maintenance mode, which requires manual intervention to bring the firewall back online.  This affects the following hardware firewall models: - PA-5400 Series firewalls - PA-7000 Series firewalls</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-3385">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-3384 – A vulnerability in Palo Alto Networks PAN-OS software enables a remote attacker ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-3384</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-3384</guid>
    <pubDate>Wed, 10 Apr 2024 17:15:57 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-3384</strong></p>
  <p>A vulnerability in Palo Alto Networks PAN-OS software enables a remote attacker to reboot PAN-OS firewalls when receiving Windows New Technology LAN Manager (NTLM) packets from Windows servers. Repeated attacks eventually cause the firewall to enter maintenance mode, which requires manual intervention to bring the firewall back online.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-1286</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-3384">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-3383 – A vulnerability in how Palo Alto Networks PAN-OS software processes data receive...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-3383</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-3383</guid>
    <pubDate>Wed, 10 Apr 2024 17:15:57 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-3383</strong></p>
  <p>A vulnerability in how Palo Alto Networks PAN-OS software processes data received from Cloud Identity Engine (CIE) agents enables modification of User-ID groups. This impacts user access to network resources where users may be inappropriately denied or allowed access to resources based on your existing Security Policy rules.</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-282</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-3383">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-3382 – A memory leak exists in Palo Alto Networks PAN-OS software that enables an attac...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-3382</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-3382</guid>
    <pubDate>Wed, 10 Apr 2024 17:15:56 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-3382</strong></p>
  <p>A memory leak exists in Palo Alto Networks PAN-OS software that enables an attacker to send a burst of crafted packets through the firewall that eventually prevents the firewall from processing traffic. This issue applies only to PA-5400 Series devices that are running PAN-OS software with the SSL Forward Proxy feature enabled.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-770</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-3382">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-0011 – A reflected cross-site scripting (XSS) vulnerability in the Captive Portal featu...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-0011</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-0011</guid>
    <pubDate>Wed, 14 Feb 2024 18:15:47 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-0011</strong></p>
  <p>A reflected cross-site scripting (XSS) vulnerability in the Captive Portal feature of Palo Alto Networks PAN-OS software enables execution of malicious JavaScript (in the context of an authenticated Captive Portal user’s browser) if a user clicks on a malicious link, allowing phishing attacks that could lead to credential theft.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-0011">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-0010 – A reflected cross-site scripting (XSS) vulnerability in the GlobalProtect portal...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-0010</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-0010</guid>
    <pubDate>Wed, 14 Feb 2024 18:15:47 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-0010</strong></p>
  <p>A reflected cross-site scripting (XSS) vulnerability in the GlobalProtect portal feature of Palo Alto Networks PAN-OS software enables execution of malicious JavaScript (in the context of a user’s browser) if a user clicks on a malicious link, allowing phishing attacks that could lead to credential theft.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-0010">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-0009 – An improper verification vulnerability in the GlobalProtect gateway feature of P...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-0009</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-0009</guid>
    <pubDate>Wed, 14 Feb 2024 18:15:47 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-0009</strong></p>
  <p>An improper verification vulnerability in the GlobalProtect gateway feature of Palo Alto Networks PAN-OS software enables a malicious user with stolen credentials to establish a VPN connection from an unauthorized IP address.</p>
  <p><strong>CVSS:</strong> 6.3 · <strong>CWE:</strong> CWE-940</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-0009">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-0008 – Web sessions in the management interface in Palo Alto Networks PAN-OS software d...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-0008</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-0008</guid>
    <pubDate>Wed, 14 Feb 2024 18:15:47 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-0008</strong></p>
  <p>Web sessions in the management interface in Palo Alto Networks PAN-OS software do not expire in certain situations, making it susceptible to unauthorized access.</p>
  <p><strong>CVSS:</strong> 6.6 · <strong>CWE:</strong> CWE-613</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-0008">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-0007 – A cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS software...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-0007</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-0007</guid>
    <pubDate>Wed, 14 Feb 2024 18:15:47 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-0007</strong></p>
  <p>A cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS software enables a malicious authenticated read-write administrator to store a JavaScript payload using the web interface on Panorama appliances. This enables the impersonation of another authenticated administrator.</p>
  <p><strong>CVSS:</strong> 6.8 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-0007">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-6795 – An OS command injection vulnerability in Palo Alto Networks PAN-OS software enab...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-6795</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-6795</guid>
    <pubDate>Wed, 13 Dec 2023 19:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-6795</strong></p>
  <p>An OS command injection vulnerability in Palo Alto Networks PAN-OS software enables an authenticated administrator to disrupt system processes and potentially execute arbitrary code with limited privileges on the firewall.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-6795">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-6794 – An arbitrary file upload vulnerability in Palo Alto Networks PAN-OS software ena...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-6794</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-6794</guid>
    <pubDate>Wed, 13 Dec 2023 19:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-6794</strong></p>
  <p>An arbitrary file upload vulnerability in Palo Alto Networks PAN-OS software enables an authenticated read-write administrator with access to the web interface to disrupt system processes and potentially execute arbitrary code with limited privileges on the firewall.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-6794">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2023-6793 – An improper privilege management vulnerability in Palo Alto Networks PAN-OS soft...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-6793</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-6793</guid>
    <pubDate>Wed, 13 Dec 2023 19:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2023-6793</strong></p>
  <p>An improper privilege management vulnerability in Palo Alto Networks PAN-OS software enables an authenticated read-only administrator to revoke active XML API keys from the firewall and disrupt XML API usage.</p>
  <p><strong>CVSS:</strong> 2.7 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-6793">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-6792 – An OS command injection vulnerability in the XML API of Palo Alto Networks PAN-O...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-6792</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-6792</guid>
    <pubDate>Wed, 13 Dec 2023 19:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-6792</strong></p>
  <p>An OS command injection vulnerability in the XML API of Palo Alto Networks PAN-OS software enables an authenticated API user to disrupt system processes and potentially execute arbitrary code with limited privileges on the firewall.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-88</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-6792">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-6791 – A credential disclosure vulnerability in Palo Alto Networks PAN-OS software enab...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-6791</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-6791</guid>
    <pubDate>Wed, 13 Dec 2023 19:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-6791</strong></p>
  <p>A credential disclosure vulnerability in Palo Alto Networks PAN-OS software enables an authenticated read-only administrator to obtain the plaintext credentials of stored external system integrations such as LDAP, SCP, RADIUS, TACACS+, and SNMP from the web interface.</p>
  <p><strong>CVSS:</strong> 4.9 · <strong>CWE:</strong> CWE-701</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-6791">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-6790 – A DOM-Based cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-O...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-6790</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-6790</guid>
    <pubDate>Wed, 13 Dec 2023 19:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-6790</strong></p>
  <p>A DOM-Based cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS software enables a remote attacker to execute a JavaScript payload in the context of an administrator’s browser when they view a specifically crafted link to the PAN-OS web interface.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-6790">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-6789 – A cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS software...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-6789</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-6789</guid>
    <pubDate>Wed, 13 Dec 2023 19:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-6789</strong></p>
  <p>A cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS software enables a malicious authenticated read-write administrator to store a JavaScript payload using the web interface. Then, when viewed by a properly authenticated administrator, the JavaScript payload executes and disguises all associated actions as performed by that unsuspecting authenticated administrator.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-6789">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-38046 – A vulnerability exists in Palo Alto Networks PAN-OS software that enables an aut...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-38046</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-38046</guid>
    <pubDate>Wed, 12 Jul 2023 17:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-38046</strong></p>
  <p>A vulnerability exists in Palo Alto Networks PAN-OS software that enables an authenticated administrator with the privilege to commit a specifically created configuration to read local files and resources from the system.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-610</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-38046">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-0010 – A reflected cross-site scripting (XSS) vulnerability in the Captive Portal featu...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-0010</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-0010</guid>
    <pubDate>Wed, 14 Jun 2023 17:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-0010</strong></p>
  <p>A reflected cross-site scripting (XSS) vulnerability in the Captive Portal feature of Palo Alto Networks PAN-OS software can allow a JavaScript payload to be executed in the context of an authenticated Captive Portal user’s browser when they click on a specifically crafted link.</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-0010">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-0008 – A file disclosure vulnerability in Palo Alto Networks PAN-OS software enables an...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-0008</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-0008</guid>
    <pubDate>Wed, 10 May 2023 17:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-0008</strong></p>
  <p>A file disclosure vulnerability in Palo Alto Networks PAN-OS software enables an authenticated read-write administrator with access to the web interface to export local files from the firewall through a race condition.</p>
  <p><strong>CVSS:</strong> 4.4 · <strong>CWE:</strong> CWE-73</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-0008">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-0007 – A cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS software...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-0007</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-0007</guid>
    <pubDate>Wed, 10 May 2023 17:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-0007</strong></p>
  <p>A cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS software on Panorama appliances enables an authenticated read-write administrator to store a JavaScript payload in the web interface that will execute in the context of another administrator’s browser when viewed.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-80</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-0007">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-0005 – A vulnerability in Palo Alto Networks PAN-OS software enables an authenticated a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-0005</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-0005</guid>
    <pubDate>Wed, 12 Apr 2023 17:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-0005</strong></p>
  <p>A vulnerability in Palo Alto Networks PAN-OS software enables an authenticated administrator to expose the plaintext values of secrets stored in the device configuration and encrypted API keys.</p>
  <p><strong>CVSS:</strong> 4.1 · <strong>CWE:</strong> CWE-497</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-0005">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-0004 – A local file deletion vulnerability in Palo Alto Networks PAN-OS software enable...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-0004</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-0004</guid>
    <pubDate>Wed, 12 Apr 2023 17:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-0004</strong></p>
  <p>A local file deletion vulnerability in Palo Alto Networks PAN-OS software enables an authenticated administrator to delete files from the local file system with elevated privileges.  These files can include logs and system components that impact the integrity and availability of PAN-OS software.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-703</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-0004">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-0030 – An authentication bypass vulnerability in the Palo Alto Networks PAN-OS 8.1 web ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-0030</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-0030</guid>
    <pubDate>Wed, 12 Oct 2022 17:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-0030</strong></p>
  <p>An authentication bypass vulnerability in the Palo Alto Networks PAN-OS 8.1 web interface allows a network-based attacker with specific knowledge of the target firewall or Panorama appliance to impersonate an existing PAN-OS administrator and perform privileged actions.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-290</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-0030">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-0024 – A vulnerability exists in Palo Alto Networks PAN-OS software that enables an aut...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-0024</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-0024</guid>
    <pubDate>Wed, 11 May 2022 17:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-0024</strong></p>
  <p>A vulnerability exists in Palo Alto Networks PAN-OS software that enables an authenticated network-based PAN-OS administrator to upload a specifically created configuration that disrupts system processes and potentially execute arbitrary code with root privileges when the configuration is committed on both hardware and virtual firewalls. This issue does not impact Panorama appliances or Prisma Ac…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-138</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-0024">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-0023 – An improper handling of exceptional conditions vulnerability exists in the DNS p...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-0023</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-0023</guid>
    <pubDate>Wed, 13 Apr 2022 19:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-0023</strong></p>
  <p>An improper handling of exceptional conditions vulnerability exists in the DNS proxy feature of Palo Alto Networks PAN-OS software that enables a meddler-in-the-middle (MITM) to send specifically crafted traffic to the firewall that causes the service to restart unexpectedly. Repeated attempts to send this request result in denial-of-service to all PAN-OS services by restarting the device in main…</p>
  <p><strong>CVSS:</strong> 5.9 · <strong>CWE:</strong> CWE-755</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-0023">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-0022 – Usage of a weak cryptographic algorithm in Palo Alto Networks PAN-OS software wh...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-0022</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-0022</guid>
    <pubDate>Wed, 09 Mar 2022 18:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-0022</strong></p>
  <p>Usage of a weak cryptographic algorithm in Palo Alto Networks PAN-OS software where the password hashes of administrator and local user accounts are not created with a sufficient level of computational effort, which allows for password cracking attacks on accounts in normal (non-FIPS-CC) operational mode. An attacker must have access to the account password hashes to take advantage of this weakne…</p>
  <p><strong>CVSS:</strong> 4.1 · <strong>CWE:</strong> CWE-916</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-0022">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-3061 – An OS command injection vulnerability in the Palo Alto Networks PAN-OS command l...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-3061</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-3061</guid>
    <pubDate>Wed, 10 Nov 2021 17:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-3061</strong></p>
  <p>An OS command injection vulnerability in the Palo Alto Networks PAN-OS command line interface (CLI) enables an authenticated administrator with access to the CLI to execute arbitrary OS commands to escalate privileges. This issue impacts: PAN-OS 8.1 versions earlier than PAN-OS 8.1.20-h1; PAN-OS 9.0 versions earlier than PAN-OS 9.0.14-h3; PAN-OS 9.1 versions earlier than PAN-OS 9.1.11-h2; PAN-OS…</p>
  <p><strong>CVSS:</strong> 6.4 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-3061">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-3059 – An OS command injection vulnerability in the Palo Alto Networks PAN-OS managemen...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-3059</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-3059</guid>
    <pubDate>Wed, 10 Nov 2021 17:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-3059</strong></p>
  <p>An OS command injection vulnerability in the Palo Alto Networks PAN-OS management interface exists when performing dynamic updates. This vulnerability enables a man-in-the-middle attacker to execute arbitrary OS commands to escalate privileges. This issue impacts: PAN-OS 8.1 versions earlier than PAN-OS 8.1.20-h1; PAN-OS 9.0 versions earlier than PAN-OS 9.0.14-h3; PAN-OS 9.1 versions earlier than…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-3059">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-3058 – An OS command injection vulnerability in the Palo Alto Networks PAN-OS web inter...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-3058</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-3058</guid>
    <pubDate>Wed, 10 Nov 2021 17:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-3058</strong></p>
  <p>An OS command injection vulnerability in the Palo Alto Networks PAN-OS web interface enables an authenticated administrator with permissions to use XML API the ability to execute arbitrary OS commands to escalate privileges. This issue impacts: PAN-OS 8.1 versions earlier than PAN-OS 8.1.20-h1; PAN-OS 9.0 versions earlier than PAN-OS 9.0.14-h3; PAN-OS 9.1 versions earlier than PAN-OS 9.1.11-h2; P…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-3058">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-3056 – A memory corruption vulnerability in Palo Alto Networks PAN-OS GlobalProtect Cli...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-3056</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-3056</guid>
    <pubDate>Wed, 10 Nov 2021 17:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-3056</strong></p>
  <p>A memory corruption vulnerability in Palo Alto Networks PAN-OS GlobalProtect Clientless VPN enables an authenticated attacker to execute arbitrary code with root user privileges during SAML authentication. This issue impacts: PAN-OS 8.1 versions earlier than PAN-OS 8.1.20; PAN-OS 9.0 versions earlier than PAN-OS 9.0.14; PAN-OS 9.1 versions earlier than PAN-OS 9.1.9; PAN-OS 10.0 versions earlier t…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-120</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-3056">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-3055 – An improper restriction of XML external entity (XXE) reference vulnerability in ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-3055</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-3055</guid>
    <pubDate>Wed, 08 Sep 2021 17:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-3055</strong></p>
  <p>An improper restriction of XML external entity (XXE) reference vulnerability in the Palo Alto Networks PAN-OS web interface enables an authenticated administrator to read any arbitrary file from the file system and send a specifically crafted request to the firewall that causes the service to crash. Repeated attempts to send this request result in denial of service to all PAN-OS services by resta…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-3055">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-3054 – A time-of-check to time-of-use (TOCTOU) race condition vulnerability in the Palo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-3054</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-3054</guid>
    <pubDate>Wed, 08 Sep 2021 17:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-3054</strong></p>
  <p>A time-of-check to time-of-use (TOCTOU) race condition vulnerability in the Palo Alto Networks PAN-OS web interface enables an authenticated administrator with permission to upload plugins to execute arbitrary code with root user privileges. This issue impacts: PAN-OS 8.1 versions earlier than PAN-OS 8.1.20; PAN-OS 9.0 versions earlier than PAN-OS 9.0.14; PAN-OS 9.1 versions earlier than PAN-OS 9…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-367</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-3054">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-3053 – An improper handling of exceptional conditions vulnerability exists in the Palo ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-3053</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-3053</guid>
    <pubDate>Wed, 08 Sep 2021 17:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-3053</strong></p>
  <p>An improper handling of exceptional conditions vulnerability exists in the Palo Alto Networks PAN-OS dataplane that enables an unauthenticated network-based attacker to send specifically crafted traffic through the firewall that causes the service to crash. Repeated attempts to send this request result in denial of service to all PAN-OS services by restarting the device and putting it into mainte…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-755</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-3053">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-3050 – An OS command injection vulnerability in the Palo Alto Networks PAN-OS web inter...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-3050</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-3050</guid>
    <pubDate>Wed, 11 Aug 2021 17:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-3050</strong></p>
  <p>An OS command injection vulnerability in the Palo Alto Networks PAN-OS web interface enables an authenticated administrator to execute arbitrary OS commands to escalate privileges. This issue impacts: PAN-OS 9.0 version 9.0.10 through PAN-OS 9.0.14; PAN-OS 9.1 version 9.1.4 through PAN-OS 9.1.10; PAN-OS 10.0 version 10.0.7 and earlier PAN-OS 10.0 versions; PAN-OS 10.1 version 10.1.0 through PAN-O…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-3050">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-3047 – A cryptographically weak pseudo-random number generator (PRNG) is used during au...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-3047</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-3047</guid>
    <pubDate>Wed, 11 Aug 2021 17:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-3047</strong></p>
  <p>A cryptographically weak pseudo-random number generator (PRNG) is used during authentication to the Palo Alto Networks PAN-OS web interface. This enables an authenticated attacker, with the capability to observe their own authentication secrets over a long duration on the PAN-OS appliance, to impersonate another authenticated web interface administrator's session. This issue impacts: PAN-OS 8.1 v…</p>
  <p><strong>CVSS:</strong> 4.2 · <strong>CWE:</strong> CWE-338</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-3047">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-3046 – An improper authentication vulnerability exists in Palo Alto Networks PAN-OS sof...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-3046</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-3046</guid>
    <pubDate>Wed, 11 Aug 2021 17:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-3046</strong></p>
  <p>An improper authentication vulnerability exists in Palo Alto Networks PAN-OS software that enables a SAML authenticated attacker to impersonate any other user in the GlobalProtect Portal and GlobalProtect Gateway when they are configured to use SAML authentication. This issue impacts: PAN-OS 8.1 versions earlier than PAN-OS 8.1.19; PAN-OS 9.0 versions earlier than PAN-OS 9.0.14; PAN-OS 9.1 versio…</p>
  <p><strong>CVSS:</strong> 6.8 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-3046">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-3045 – An OS command argument injection vulnerability in the Palo Alto Networks PAN-OS ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-3045</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-3045</guid>
    <pubDate>Wed, 11 Aug 2021 17:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-3045</strong></p>
  <p>An OS command argument injection vulnerability in the Palo Alto Networks PAN-OS web interface enables an authenticated administrator to read any arbitrary file from the file system. This issue impacts: PAN-OS 8.1 versions earlier than PAN-OS 8.1.19; PAN-OS 9.0 versions earlier than PAN-OS 9.0.14; PAN-OS 9.1 versions earlier than PAN-OS 9.1.10. PAN-OS 10.0 and later versions are not impacted.</p>
  <p><strong>CVSS:</strong> 4.9 · <strong>CWE:</strong> CWE-88</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-3045">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2021-3037 – An information exposure through log file vulnerability exists in Palo Alto Netwo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-3037</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-3037</guid>
    <pubDate>Tue, 20 Apr 2021 04:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2021-3037</strong></p>
  <p>An information exposure through log file vulnerability exists in Palo Alto Networks PAN-OS software where the connection details for a scheduled configuration export are logged in system logs. Logged information includes the cleartext username, password, and IP address used to export the PAN-OS configuration to the destination server.</p>
  <p><strong>CVSS:</strong> 2.3 · <strong>CWE:</strong> CWE-534</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-3037">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-3036 – An information exposure through log file vulnerability exists in Palo Alto Netwo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-3036</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-3036</guid>
    <pubDate>Tue, 20 Apr 2021 04:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-3036</strong></p>
  <p>An information exposure through log file vulnerability exists in Palo Alto Networks PAN-OS software where secrets in PAN-OS XML API requests are logged in cleartext to the web server logs when the API is used incorrectly. This vulnerability applies only to PAN-OS appliances that are configured to use the PAN-OS XML API and exists only when a client includes a duplicate API parameter in API reques…</p>
  <p><strong>CVSS:</strong> 4.4 · <strong>CWE:</strong> CWE-532</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-3036">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-3032 – An information exposure through log file vulnerability exists in Palo Alto Netwo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-3032</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-3032</guid>
    <pubDate>Wed, 13 Jan 2021 18:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-3032</strong></p>
  <p>An information exposure through log file vulnerability exists in Palo Alto Networks PAN-OS software where configuration secrets for the “http”, “email”, and “snmptrap” v3 log forwarding server profiles can be logged to the logrcvr.log system log. Logged information may include up to 1024 bytes of the configuration including the username and password in an encrypted form and private keys used in a…</p>
  <p><strong>CVSS:</strong> 4.4 · <strong>CWE:</strong> CWE-532</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-3032">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-2050 – An authentication bypass vulnerability exists in the GlobalProtect SSL VPN compo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-2050</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-2050</guid>
    <pubDate>Thu, 12 Nov 2020 00:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-2050</strong></p>
  <p>An authentication bypass vulnerability exists in the GlobalProtect SSL VPN component of Palo Alto Networks PAN-OS software that allows an attacker to bypass all client certificate checks with an invalid certificate. A remote attacker can successfully authenticate as any user and gain access to restricted VPN network resources when the gateway or portal is configured to rely entirely on certificat…</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-285</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-2050">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2020-2048 – An information exposure through log file vulnerability exists where the password...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-2048</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-2048</guid>
    <pubDate>Thu, 12 Nov 2020 00:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2020-2048</strong></p>
  <p>An information exposure through log file vulnerability exists where the password for the configured system proxy server for a PAN-OS appliance may be displayed in cleartext when using the CLI in Palo Alto Networks PAN-OS software. This issue impacts: PAN-OS 8.1 versions earlier than PAN-OS 8.1.17; PAN-OS 9.0 versions earlier than PAN-OS 9.0.11; PAN-OS 9.1 versions earlier than PAN-OS 9.1.2.</p>
  <p><strong>CVSS:</strong> 3.3 · <strong>CWE:</strong> CWE-532</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-2048">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2020-2044 – An information exposure through log file vulnerability where an administrator's ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-2044</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-2044</guid>
    <pubDate>Wed, 09 Sep 2020 17:15:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2020-2044</strong></p>
  <p>An information exposure through log file vulnerability where an administrator's password or other sensitive information may be logged in cleartext while using the CLI in Palo Alto Networks PAN-OS software. The opcmdhistory.log file was introduced to track operational command (op-command) usage but did not mask all sensitive information. The opcmdhistory.log file is removed in PAN-OS 9.1 and later…</p>
  <p><strong>CVSS:</strong> 3.3 · <strong>CWE:</strong> CWE-532</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-2044">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2020-2043 – An information exposure through log file vulnerability where sensitive fields ar...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-2043</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-2043</guid>
    <pubDate>Wed, 09 Sep 2020 17:15:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2020-2043</strong></p>
  <p>An information exposure through log file vulnerability where sensitive fields are recorded in the configuration log without masking on Palo Alto Networks PAN-OS software when the after-change-detail custom syslog field is enabled for configuration logs and the sensitive field appears multiple times in one log entry. The first instance of the sensitive field is masked but subsequent instances are…</p>
  <p><strong>CVSS:</strong> 3.3 · <strong>CWE:</strong> CWE-532</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-2043">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-2041 – An insecure configuration of the appweb daemon of Palo Alto Networks PAN-OS 8.1 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-2041</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-2041</guid>
    <pubDate>Wed, 09 Sep 2020 17:15:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-2041</strong></p>
  <p>An insecure configuration of the appweb daemon of Palo Alto Networks PAN-OS 8.1 allows a remote unauthenticated user to send a specifically crafted request to the device that causes the appweb service to crash. Repeated attempts to send this request result in denial of service to all PAN-OS services by restarting the device and putting it into maintenance mode. This issue impacts all versions of…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-16</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-2041">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
