Vulnerabilidades en Palo Alto Networks

330 resultados
Análisis Vexday

Das 316 CVEs catalogadas para Palo Alto Networks, 13 estão confirmadas em exploração ativa no catálogo KEV da CISA, representando uma taxa 9,1 vezes acima da média geral do catálogo — sinal de que vulnerabilidades nesse vendor atraem exploração real com frequência desproporcional. A CVE mais crítica em atividade é a CVE-2024-3400, que atingiu EPSS máximo de 1,0, indicando probabilidade extremamente elevada de exploração observada ou iminente. O tipo de falha mais recorrente é CWE-78 (injeção de comandos no sistema operacional), uma classe de vulnerabilidade com alto potencial de impacto em appliances de segurança de perímetro. Com 17 CVEs críticas, 15 com PoC pública e 39 surgidas nos últimos 90 dias, equipes responsáveis por ambientes que utilizam produtos Palo Alto Networks devem priorizar ciclos curtos de patching e monitorar ativamente os indicadores de exploração.

CVE-2020-1990HIGHPAN-OS: Buffer overflow in the management serverEPSS 2.1%CVE-2020-2009HIGHPAN-OS: Panorama SD WAN arbitrary file creationEPSS 2.0%CVE-2020-2012HIGHPAN-OS: Panorama: XML external entity reference ('XXE') vulnerability leads the to information leakEPSS 1.9%CVE-2025-0111HIGHPAN-OS: Authenticated File Read Vulnerability in the Management Web InterfaceEPSS 1.9%KEVCVE-2018-10140The PAN-OS Management Web Interface in Palo Alto Networks PAN-OS 8.1.2 and earlier may allow an authenticated user to shut down all managemeEPSS 1.9%CVE-2020-2015HIGHPAN-OS: Buffer overflow in the management serverEPSS 1.9%CVE-2020-2006HIGHPAN-OS: Buffer overflow in management server payload parserEPSS 1.9%CVE-2020-2011HIGHPAN-OS: Panorama registration denial of serviceEPSS 1.8%CVE-2020-2028HIGHPAN-OS: OS command injection vulnerability in FIPS-CC mode certificate verificationEPSS 1.8%CVE-2021-3050HIGHPAN-OS: OS Command Injection Vulnerability in Web InterfaceEPSS 1.8%CVE-2020-2029HIGHPAN-OS: OS command injection vulnerability in management interface certificate generatorEPSS 1.8%CVE-2022-0020MEDIUMCortex XSOAR: Stored Cross-Site Scripting (XSS) Vulnerability in Web InterfaceEPSS 1.7%CVE-2019-17440CRITICALPAN-OS on PA-7000 Series: Improper restriction of communication to Log Forwarding Card (LFC) allows root accessEPSS 1.7%CVE-2021-3058HIGHPAN-OS: OS Command Injection Vulnerability in Web Interface XML APIEPSS 1.6%CVE-2021-3059HIGHPAN-OS: OS Command Injection Vulnerability When Performing Dynamic UpdatesEPSS 1.5%CVE-2018-10139The PAN-OS response for GlobalProtect Gateway in Palo Alto Networks PAN-OS 6.1.21 and earlier, PAN-OS 7.1.18 and earlier, PAN-OS 8.0.11 and EPSS 1.5%CVE-2022-0024HIGHPAN-OS: Improper Neutralization Vulnerability Leads to Unintended Program Execution During Configuration CommitEPSS 1.5%CVE-2021-3056HIGHPAN-OS: Memory Corruption Vulnerability in GlobalProtect Clientless VPN During SAML AuthenticationEPSS 1.5%CVE-2024-5921MEDIUMGlobalProtect App: Insufficient Certificate Validation Leads to Privilege EscalationEPSS 1.5%CVE-2021-3057HIGHGlobalProtect App: Buffer Overflow Vulnerability When Connecting to Portal or GatewayEPSS 1.4%