Palo Alto Networks PAN-OS vulnerabilities
184 known vulnerabilities affecting palo_alto_networks/pan-os.
Total CVEs
184
CISA KEV
10
actively exploited
Public exploits
10
Exploited in wild
11
Severity breakdown
CRITICAL18HIGH80MEDIUM73LOW13
Vulnerabilities
Page 10 of 10
CVE-2024-2433P4LOWCVSS 2.7≥ 9.0, < 9.0.17-h4≥ 9.1, < 9.1.17+3 more2024-03-13
CVE-2024-2433 [LOW] CWE-269 CVE-2024-2433: An improper authorization vulnerability in Palo Alto Networks Panorama software enables an authentic
An improper authorization vulnerability in Palo Alto Networks Panorama software enables an authenticated read-only administrator to upload files using the web interface and completely fill one of the disk partitions with those uploaded files, which prevents the ability to log into the web interface or to download PAN-OS, WildFire, and content images.
T
nvd
CVE-2023-6793P4LOWCVSS 2.7≥ 9.0, < 9.0.17-h4≥ 9.1, < 9.1.17+4 more2023-12-13
CVE-2023-6793 [LOW] CWE-269 CVE-2023-6793: An improper privilege management vulnerability in Palo Alto Networks PAN-OS software enables an auth
An improper privilege management vulnerability in Palo Alto Networks PAN-OS software enables an authenticated read-only administrator to revoke active XML API keys from the firewall and disrupt XML API usage.
nvd
CVE-2025-4614P4LOWCVSS 2.7≥ 11.2.0, < 11.2.8≥ 11.1.0, < 11.1.12+1 more2025-10-09
CVE-2025-4614 [LOW] CWE-497 CVE-2025-4614: An information disclosure vulnerability in Palo Alto Networks PAN-OS® software enables an authentica
An information disclosure vulnerability in Palo Alto Networks PAN-OS® software enables an authenticated administrator to view session tokens of users authenticated to the firewall web UI. This may allow impersonation of users whose session tokens are leaked.
The security risk posed by this issue is significantly minimized when CLI access is restricted t
nvd
CVE-2021-3037P4LOWCVSS 2.3≥ 8.1, < 8.1.19≥ 9.0, < 9.0.13+1 more2021-04-20
CVE-2021-3037 [LOW] CWE-534 CVE-2021-3037: An information exposure through log file vulnerability exists in Palo Alto Networks PAN-OS software
An information exposure through log file vulnerability exists in Palo Alto Networks PAN-OS software where the connection details for a scheduled configuration export are logged in system logs. Logged information includes the cleartext username, password, and IP address used to export the PAN-OS configuration to the destination server.
nvd
← Previous10 / 10