Vulnerabilidades en Palo Alto Networks

330 resultados
Análisis Vexday

Das 316 CVEs catalogadas para Palo Alto Networks, 13 estão confirmadas em exploração ativa no catálogo KEV da CISA, representando uma taxa 9,1 vezes acima da média geral do catálogo — sinal de que vulnerabilidades nesse vendor atraem exploração real com frequência desproporcional. A CVE mais crítica em atividade é a CVE-2024-3400, que atingiu EPSS máximo de 1,0, indicando probabilidade extremamente elevada de exploração observada ou iminente. O tipo de falha mais recorrente é CWE-78 (injeção de comandos no sistema operacional), uma classe de vulnerabilidade com alto potencial de impacto em appliances de segurança de perímetro. Com 17 CVEs críticas, 15 com PoC pública e 39 surgidas nos últimos 90 dias, equipes responsáveis por ambientes que utilizam produtos Palo Alto Networks devem priorizar ciclos curtos de patching e monitorar ativamente os indicadores de exploração.

CVE-2024-8686HIGHPAN-OS: Command Injection VulnerabilityEPSS 1.4%CVE-2021-3044CRITICALCortex XSOAR: Unauthorized Usage of the REST APIEPSS 1.4%CVE-2026-0261MEDIUMPAN-OS: Authenticated Admin Command Injection VulnerabilityEPSS 1.4%CVE-2026-0273MEDIUMPAN-OS: Authenticated Admin Command Injection Vulnerability via CLI or Web UIEPSS 1.3%CVE-2020-1999MEDIUMPAN-OS: Threat signatures are evaded by specifically crafted packetsEPSS 1.3%CVE-2020-2001HIGHPAN-OS: Panorama External control of file vulnerability leads to privilege escalationEPSS 1.3%CVE-2020-2018CRITICALPAN-OS: Panorama authentication bypass vulnerabilityEPSS 1.3%CVE-2023-0003MEDIUMCortex XSOAR: Local File Disclosure Vulnerability in the Cortex XSOAR ServerEPSS 1.3%CVE-2020-2002HIGHPAN-OS: Spoofed Kerberos key distribution center authentication bypassEPSS 1.3%CVE-2021-3035MEDIUMBridgecrew Checkov: Unsafe deserialization of Terraform files allows code executionEPSS 1.3%CVE-2021-3040MEDIUMBridgecrew Checkov: Unsafe deserialization of Terraform files allows code executionEPSS 1.3%CVE-2025-0110HIGHPAN-OS OpenConfig Plugin: Command Injection Vulnerability in OpenConfig PluginEPSS 1.3%CVE-2024-5914HIGHCortex XSOAR: Command Injection in CommonScripts PackEPSS 1.2%CVE-2020-2022HIGHPAN-OS: Panorama session disclosure during context switch into managed deviceEPSS 1.2%CVE-2021-3033CRITICALPrisma Cloud Compute: SAML Authentication Bypass Vulnerability in ConsoleEPSS 1.2%CVE-2019-1566The PAN-OS management web interface in PAN-OS 7.1.21 and earlier, PAN-OS 8.0.14 and earlier, and PAN-OS 8.1.5 and earlier, may allow an unauEPSS 1.2%CVE-2020-1995MEDIUMPAN-OS: Management server rasmgr denial of serviceEPSS 1.1%CVE-2023-6792MEDIUMPAN-OS: OS Command Injection Vulnerability in the XML APIEPSS 1.1%CVE-2023-6795MEDIUMPAN-OS: OS Command Injection Vulnerability in the Web InterfaceEPSS 1.1%CVE-2020-2031MEDIUMPAN-OS: Integer underflow in the management interfaceEPSS 1.1%