Vulnerabilidades em Palo Alto Networks

351 resultados
Análise Vexday

Das 316 CVEs catalogadas para Palo Alto Networks, 13 estão confirmadas em exploração ativa no catálogo KEV da CISA, representando uma taxa 9,1 vezes acima da média geral do catálogo — sinal de que vulnerabilidades nesse vendor atraem exploração real com frequência desproporcional. A CVE mais crítica em atividade é a CVE-2024-3400, que atingiu EPSS máximo de 1,0, indicando probabilidade extremamente elevada de exploração observada ou iminente. O tipo de falha mais recorrente é CWE-78 (injeção de comandos no sistema operacional), uma classe de vulnerabilidade com alto potencial de impacto em appliances de segurança de perímetro. Com 17 CVEs críticas, 15 com PoC pública e 39 surgidas nos últimos 90 dias, equipes responsáveis por ambientes que utilizam produtos Palo Alto Networks devem priorizar ciclos curtos de patching e monitorar ativamente os indicadores de exploração.

CVE-2019-1578Cross-site scripting vulnerability in Palo Alto Networks MineMeld version 0.9.60 and earlier may allow a remote attacker able to convince anEPSS 1.4%CVE-2021-3057HIGHGlobalProtect App: Buffer Overflow Vulnerability When Connecting to Portal or GatewayEPSS 1.4%CVE-2024-8686HIGHPAN-OS: Command Injection VulnerabilityEPSS 1.4%CVE-2021-3044CRITICALCortex XSOAR: Unauthorized Usage of the REST APIEPSS 1.4%CVE-2026-0261MEDIUMPAN-OS: Authenticated Admin Command Injection VulnerabilityEPSS 1.4%CVE-2026-0273MEDIUMPAN-OS: Authenticated Admin Command Injection Vulnerability via CLI or Web UIEPSS 1.3%CVE-2020-1999MEDIUMPAN-OS: Threat signatures are evaded by specifically crafted packetsEPSS 1.3%CVE-2020-2001HIGHPAN-OS: Panorama External control of file vulnerability leads to privilege escalationEPSS 1.3%CVE-2023-0003MEDIUMCortex XSOAR: Local File Disclosure Vulnerability in the Cortex XSOAR ServerEPSS 1.3%CVE-2020-2018CRITICALPAN-OS: Panorama authentication bypass vulnerabilityEPSS 1.3%CVE-2020-2002HIGHPAN-OS: Spoofed Kerberos key distribution center authentication bypassEPSS 1.3%CVE-2021-3035MEDIUMBridgecrew Checkov: Unsafe deserialization of Terraform files allows code executionEPSS 1.3%CVE-2021-3040MEDIUMBridgecrew Checkov: Unsafe deserialization of Terraform files allows code executionEPSS 1.3%CVE-2025-0110HIGHPAN-OS OpenConfig Plugin: Command Injection Vulnerability in OpenConfig PluginEPSS 1.3%CVE-2019-1577Code injection vulnerability in Palo Alto Networks Traps 5.0.5 and earlier may allow an authenticated attacker to inject arbitrary JavaScripEPSS 1.2%CVE-2024-5914HIGHCortex XSOAR: Command Injection in CommonScripts PackEPSS 1.2%CVE-2020-2022HIGHPAN-OS: Panorama session disclosure during context switch into managed deviceEPSS 1.2%CVE-2021-3033CRITICALPrisma Cloud Compute: SAML Authentication Bypass Vulnerability in ConsoleEPSS 1.2%CVE-2019-1566The PAN-OS management web interface in PAN-OS 7.1.21 and earlier, PAN-OS 8.0.14 and earlier, and PAN-OS 8.1.5 and earlier, may allow an unauEPSS 1.2%CVE-2023-6792MEDIUMPAN-OS: OS Command Injection Vulnerability in the XML APIEPSS 1.1%