Vulnerabilidades em Palo Alto Networks

351 resultados
Análise Vexday

Das 316 CVEs catalogadas para Palo Alto Networks, 13 estão confirmadas em exploração ativa no catálogo KEV da CISA, representando uma taxa 9,1 vezes acima da média geral do catálogo — sinal de que vulnerabilidades nesse vendor atraem exploração real com frequência desproporcional. A CVE mais crítica em atividade é a CVE-2024-3400, que atingiu EPSS máximo de 1,0, indicando probabilidade extremamente elevada de exploração observada ou iminente. O tipo de falha mais recorrente é CWE-78 (injeção de comandos no sistema operacional), uma classe de vulnerabilidade com alto potencial de impacto em appliances de segurança de perímetro. Com 17 CVEs críticas, 15 com PoC pública e 39 surgidas nos últimos 90 dias, equipes responsáveis por ambientes que utilizam produtos Palo Alto Networks devem priorizar ciclos curtos de patching e monitorar ativamente os indicadores de exploração.

CVE-2025-0111HIGHPAN-OS: Authenticated File Read Vulnerability in the Management Web InterfaceEPSS 2.0%KEVCVE-2020-2009HIGHPAN-OS: Panorama SD WAN arbitrary file creationEPSS 2.0%CVE-2018-10140The PAN-OS Management Web Interface in Palo Alto Networks PAN-OS 8.1.2 and earlier may allow an authenticated user to shut down all managemeEPSS 1.9%CVE-2020-2012HIGHPAN-OS: Panorama: XML external entity reference ('XXE') vulnerability leads the to information leakEPSS 1.9%CVE-2020-2015HIGHPAN-OS: Buffer overflow in the management serverEPSS 1.9%CVE-2020-2006HIGHPAN-OS: Buffer overflow in management server payload parserEPSS 1.9%CVE-2018-10139The PAN-OS response for GlobalProtect Gateway in Palo Alto Networks PAN-OS 6.1.21 and earlier, PAN-OS 7.1.18 and earlier, PAN-OS 8.0.11 and EPSS 1.9%CVE-2020-2011HIGHPAN-OS: Panorama registration denial of serviceEPSS 1.8%CVE-2018-10142The Expedition Migration tool 1.0.106 and earlier may allow an unauthenticated attacker to enumerate files on the operating system.EPSS 1.8%CVE-2020-2028HIGHPAN-OS: OS command injection vulnerability in FIPS-CC mode certificate verificationEPSS 1.8%CVE-2021-3050HIGHPAN-OS: OS Command Injection Vulnerability in Web InterfaceEPSS 1.8%CVE-2020-2029HIGHPAN-OS: OS command injection vulnerability in management interface certificate generatorEPSS 1.8%CVE-2022-0020MEDIUMCortex XSOAR: Stored Cross-Site Scripting (XSS) Vulnerability in Web InterfaceEPSS 1.7%CVE-2019-17440CRITICALPAN-OS on PA-7000 Series: Improper restriction of communication to Log Forwarding Card (LFC) allows root accessEPSS 1.7%CVE-2026-0286MEDIUMPAN-OS: Authenticated Command Injection in CLIEPSS 1.7%CVE-2021-3058HIGHPAN-OS: OS Command Injection Vulnerability in Web Interface XML APIEPSS 1.6%CVE-2022-0024HIGHPAN-OS: Improper Neutralization Vulnerability Leads to Unintended Program Execution During Configuration CommitEPSS 1.5%CVE-2021-3059HIGHPAN-OS: OS Command Injection Vulnerability When Performing Dynamic UpdatesEPSS 1.5%CVE-2021-3056HIGHPAN-OS: Memory Corruption Vulnerability in GlobalProtect Clientless VPN During SAML AuthenticationEPSS 1.5%CVE-2024-5921MEDIUMGlobalProtect App: Insufficient Certificate Validation Leads to Privilege EscalationEPSS 1.5%