Vulnerabilidades em Palo Alto Networks

351 resultados
Análise Vexday

Das 316 CVEs catalogadas para Palo Alto Networks, 13 estão confirmadas em exploração ativa no catálogo KEV da CISA, representando uma taxa 9,1 vezes acima da média geral do catálogo — sinal de que vulnerabilidades nesse vendor atraem exploração real com frequência desproporcional. A CVE mais crítica em atividade é a CVE-2024-3400, que atingiu EPSS máximo de 1,0, indicando probabilidade extremamente elevada de exploração observada ou iminente. O tipo de falha mais recorrente é CWE-78 (injeção de comandos no sistema operacional), uma classe de vulnerabilidade com alto potencial de impacto em appliances de segurança de perímetro. Com 17 CVEs críticas, 15 com PoC pública e 39 surgidas nos últimos 90 dias, equipes responsáveis por ambientes que utilizam produtos Palo Alto Networks devem priorizar ciclos curtos de patching e monitorar ativamente os indicadores de exploração.

CVE-2025-0127HIGHPAN-OS: Authenticated Admin Command Injection Vulnerability in PAN-OS VM-SeriesEPSS 0.6%CVE-2025-4619MEDIUMPAN-OS: Firewall Denial of Service (DoS) Using Specially Crafted PacketsEPSS 0.6%CVE-2023-6793LOWPAN-OS: XML API Keys Revoked by Read-Only PAN-OS AdministratorEPSS 0.6%CVE-2025-0119MEDIUMCortex XDR Broker VM: Authenticated Command Injection Vulnerability in Broker VMEPSS 0.6%CVE-2023-0008MEDIUMPAN-OS: Local File Disclosure Vulnerability in the PAN-OS Web InterfaceEPSS 0.5%CVE-2021-3031MEDIUMPAN-OS: Information exposure in Ethernet data frame construction (Etherleak)EPSS 0.5%CVE-2022-0027MEDIUMCortex XSOAR: Incorrect Authorization Vulnerability When Generating ReportsEPSS 0.5%CVE-2021-3039LOWPrisma Cloud Compute: User role authorization secret for Console leaked through log file exportEPSS 0.5%CVE-2026-0229MEDIUMPAN-OS: Denial of Service in Advanced DNS Security FeatureEPSS 0.5%CVE-2024-2550HIGHPAN-OS: Firewall Denial of Service (DoS) in GlobalProtect Gateway Using a Specially Crafted PacketEPSS 0.5%CVE-2020-1977HIGHExpedition Migration Tool: Insufficient Cross Site Request Forgery protection.EPSS 0.5%CVE-2024-0010MEDIUMPAN-OS: Reflected Cross-Site Scripting (XSS) Vulnerability in GlobalProtect PortalEPSS 0.5%CVE-2025-4229MEDIUMPAN-OS: Traffic Information Disclosure VulnerabilityEPSS 0.5%CVE-2024-0008MEDIUMPAN-OS: Insufficient Session Expiration Vulnerability in the Web InterfaceEPSS 0.5%CVE-2025-0134MEDIUMCortex XDR Broker VM: Authenticated Code Injection Vulnerability in Broker VMEPSS 0.5%CVE-2021-3049LOWCortex XSOAR: Improper Authorization of Incident Investigations VulnerabilityEPSS 0.5%CVE-2024-2551HIGHPAN-OS: Firewall Denial of Service (DoS) Using a Specially Crafted PacketEPSS 0.5%CVE-2025-0106MEDIUMExpedition: Wildcard Expansion VulnerabilityEPSS 0.5%CVE-2026-0264HIGHPAN-OS: Heap-Based Buffer Overflow in DNS Proxy and DNS Server Allows Unauthenticated Remote Code ExecutionEPSS 0.5%CVE-2024-2552MEDIUMPAN-OS: Arbitrary File Delete Vulnerability in the Command Line Interface (CLI)EPSS 0.5%