Vulnerabilidades em Palo Alto Networks

351 resultados
Análise Vexday

Das 316 CVEs catalogadas para Palo Alto Networks, 13 estão confirmadas em exploração ativa no catálogo KEV da CISA, representando uma taxa 9,1 vezes acima da média geral do catálogo — sinal de que vulnerabilidades nesse vendor atraem exploração real com frequência desproporcional. A CVE mais crítica em atividade é a CVE-2024-3400, que atingiu EPSS máximo de 1,0, indicando probabilidade extremamente elevada de exploração observada ou iminente. O tipo de falha mais recorrente é CWE-78 (injeção de comandos no sistema operacional), uma classe de vulnerabilidade com alto potencial de impacto em appliances de segurança de perímetro. Com 17 CVEs críticas, 15 com PoC pública e 39 surgidas nos últimos 90 dias, equipes responsáveis por ambientes que utilizam produtos Palo Alto Networks devem priorizar ciclos curtos de patching e monitorar ativamente os indicadores de exploração.

CVE-2020-2031MEDIUMPAN-OS: Integer underflow in the management interfaceEPSS 1.1%CVE-2023-0004MEDIUMPAN-OS: Local File Deletion VulnerabilityEPSS 1.1%CVE-2021-3046MEDIUMPAN-OS: Improper SAML Authentication Vulnerability in GlobalProtect PortalEPSS 1.1%CVE-2021-3055MEDIUMPAN-OS: XML External Entity (XXE) Reference Vulnerability in the PAN-OS Web InterfaceEPSS 1.1%CVE-2019-1578Cross-site scripting vulnerability in Palo Alto Networks MineMeld version 0.9.60 and earlier may allow a remote attacker able to convince anEPSS 1.1%CVE-2026-0265HIGHPAN-OS: Authentication Bypass with Cloud Authentication Service (CAS) enabledEPSS 1.1%CVE-2020-2050HIGHPAN-OS: Authentication bypass vulnerability in GlobalProtect SSL VPN client certificate verificationEPSS 1.0%CVE-2021-3053HIGHPAN-OS: Exceptional Condition Denial-of-Service (DoS)EPSS 1.0%CVE-2020-1979HIGHPAN-OS: A format string vulnerability in PAN-OS log daemon (logd) on Panorama allows local privilege escalationEPSS 1.0%CVE-2020-1975MEDIUMMissing XML Validation in PAN-OS Web InterfaceEPSS 1.0%CVE-2025-4231HIGHPAN-OS: Authenticated Admin Command Injection Vulnerability in the Management Web InterfaceEPSS 1.0%CVE-2020-2003MEDIUMPAN-OS: Authenticated administrator can delete arbitrary system fileEPSS 0.9%CVE-2021-3063HIGHPAN-OS: Denial-of-Service (DoS) Vulnerability in GlobalProtect Portal and Gateway InterfacesEPSS 0.9%CVE-2024-3382HIGHPAN-OS: Firewall Denial of Service (DoS) via a Burst of Crafted PacketsEPSS 0.9%CVE-2021-3054HIGHPAN-OS: Unsigned Code Execution During Plugin Installation Race Condition VulnerabilityEPSS 0.9%CVE-2024-3385HIGHPAN-OS: Firewall Denial of Service (DoS) when GTP Security is DisabledEPSS 0.9%CVE-2020-1996MEDIUMPAN-OS: Panorama management server log injectionEPSS 0.9%CVE-2022-0030HIGHPAN-OS: Authentication Bypass in Web InterfaceEPSS 0.9%CVE-2019-1577Code injection vulnerability in Palo Alto Networks Traps 5.0.5 and earlier may allow an authenticated attacker to inject arbitrary JavaScripEPSS 0.9%CVE-2020-1997MEDIUMPAN-OS: GlobalProtect registration open redirectEPSS 0.9%