Palo Alto Networks PAN-OS vulnerabilities
184 known vulnerabilities affecting palo_alto_networks/pan-os.
Total CVEs
184
CISA KEV
10
actively exploited
Public exploits
10
Exploited in wild
11
Severity breakdown
CRITICAL18HIGH80MEDIUM73LOW13
Vulnerabilities
Page 9 of 10
CVE-2024-5920P4MEDIUMCVSS 4.8≥ 11.1.0, < 11.1.4≥ 11.0.0, < 11.0.6+2 more2024-11-14
CVE-2024-5920 [MEDIUM] CWE-79 CVE-2024-5920: A cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS software enables an authenti
A cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS software enables an authenticated read-write Panorama administrator to push a specially crafted configuration to a PAN-OS node. This enables impersonation of a legitimate PAN-OS administrator who can perform restricted actions on the PAN-OS node after the execution of JavaScript in
nvd
CVE-2026-0256P4MEDIUMCVSS 4.8≥ 12.1.0, < 12.1.7≥ 11.2.0, < 11.2.12+2 more2026-05-13
CVE-2026-0256 [MEDIUM] CWE-79 CVE-2026-0256: A stored cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS® software enables a m
A stored cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS® software enables a malicious authenticated administrator to store a JavaScript payload using the web interface.
This issue is applicable to PAN-OS software on PA-Series and VM-Series firewalls and on Panorama (virtual and M-Series).
Cloud NGFW and Prisma® Access are not
nvd
CVE-2026-0266P4MEDIUMCVSS 4.8≥ 12.1.0, < 12.1.5≥ 11.2.0, < 11.2.11+2 more2026-06-10
CVE-2026-0266 [MEDIUM] CWE-79 CVE-2026-0266: A cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS® software enables a maliciou
A cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS® software enables a malicious authenticated administrator to store a JavaScript payload using the web interface.
This issue is applicable to PAN-OS software on PA-Series and VM-Series firewalls and on Panorama (virtual and M-Series).
Cloud NGFW and Prisma® Access are not affected
nvd
CVE-2022-0022P4MEDIUMCVSS 4.4v9.0.*≥ 9.1, < 9.1.11+2 more2022-03-09
CVE-2022-0022 [MEDIUM] CWE-916 CVE-2022-0022: Usage of a weak cryptographic algorithm in Palo Alto Networks PAN-OS software where the password has
Usage of a weak cryptographic algorithm in Palo Alto Networks PAN-OS software where the password hashes of administrator and local user accounts are not created with a sufficient level of computational effort, which allows for password cracking attacks on accounts in normal (non-FIPS-CC) operational mode. An attacker must have access to the account pa
nvd
CVE-2023-0008P4MEDIUMCVSS 4.4≥ 8.1, < 8.1.25≥ 9.0, < 9.0.17+5 more2023-05-10
CVE-2023-0008 [MEDIUM] CWE-73 CVE-2023-0008: A file disclosure vulnerability in Palo Alto Networks PAN-OS software enables an authenticated read-
A file disclosure vulnerability in Palo Alto Networks PAN-OS software enables an authenticated read-write administrator with access to the web interface to export local files from the firewall through a race condition.
nvd
CVE-2021-3036P4MEDIUMCVSS 4.4≥ 8.1, < 8.1.19≥ 9.0, < 9.0.12+2 more2021-04-20
CVE-2021-3036 [MEDIUM] CWE-532 CVE-2021-3036: An information exposure through log file vulnerability exists in Palo Alto Networks PAN-OS software
An information exposure through log file vulnerability exists in Palo Alto Networks PAN-OS software where secrets in PAN-OS XML API requests are logged in cleartext to the web server logs when the API is used incorrectly. This vulnerability applies only to PAN-OS appliances that are configured to use the PAN-OS XML API and exists only when a client inc
nvd
CVE-2020-1994P4MEDIUMCVSS 4.4v7.1.*v8.0.*+2 more2020-05-13
CVE-2020-1994 [MEDIUM] CWE-377 CVE-2020-1994: A predictable temporary file vulnerability in PAN-OS allows a local authenticated user with shell ac
A predictable temporary file vulnerability in PAN-OS allows a local authenticated user with shell access to corrupt arbitrary system files affecting the integrity of the system. This issue affects: All versions of PAN-OS 7.1 and 8.0; PAN-OS 8.1 versions earlier than 8.1.13; PAN-OS 9.0 versions earlier than 9.0.7.
nvd
CVE-2023-6789P4MEDIUMCVSS 4.8≥ 8.1, < 8.1.26≥ 9.0, < 9.0.17-h4+5 more2023-12-13
CVE-2023-6789 [MEDIUM] CWE-79 CVE-2023-6789: A cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS software enables a malicious
A cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS software enables a malicious authenticated read-write administrator to store a JavaScript payload using the web interface. Then, when viewed by a properly authenticated administrator, the JavaScript payload executes and disguises all associated actions as performed by that unsuspec
nvd
CVE-2024-0007P4MEDIUMCVSS 4.8≥ 8.1, < 8.1.24-h1≥ 8.1, < 8.1.25+4 more2024-02-14
CVE-2024-0007 [MEDIUM] CWE-79 CVE-2024-0007: A cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS software enables a malicious
A cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS software enables a malicious authenticated read-write administrator to store a JavaScript payload using the web interface on Panorama appliances. This enables the impersonation of another authenticated administrator.
nvd
CVE-2021-3032P4MEDIUMCVSS 4.4≥ 8.1, < 8.1.18≥ 9.0, < 9.0.12+2 more2021-01-13
CVE-2021-3032 [MEDIUM] CWE-532 CVE-2021-3032: An information exposure through log file vulnerability exists in Palo Alto Networks PAN-OS software
An information exposure through log file vulnerability exists in Palo Alto Networks PAN-OS software where configuration secrets for the “http”, “email”, and “snmptrap” v3 log forwarding server profiles can be logged to the logrcvr.log system log. Logged information may include up to 1024 bytes of the configuration including the username and password in
nvd
CVE-2023-0007P4MEDIUMCVSS 4.8≥ 10.0, < 10.0.7≥ 9.1, < 9.1.16+2 more2023-05-10
CVE-2023-0007 [MEDIUM] CWE-80 CVE-2023-0007: A cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS software on Panorama applian
A cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS software on Panorama appliances enables an authenticated read-write administrator to store a JavaScript payload in the web interface that will execute in the context of another administrator’s browser when viewed.
nvd
CVE-2024-5916P4MEDIUMCVSS 4.4≥ 10.2, < 10.2.8≥ 11.0, < 11.0.42024-08-14
CVE-2024-5916 [MEDIUM] CWE-313 CVE-2024-5916: An information exposure vulnerability in Palo Alto Networks PAN-OS software enables a local system a
An information exposure vulnerability in Palo Alto Networks PAN-OS software enables a local system administrator to unintentionally disclose secrets, passwords, and tokens of external systems. A read-only administrator who has access to the config log, can read secrets, passwords, and tokens to external systems.
nvd
CVE-2025-0124P4LOWCVSS 3.8≥ 11.2.0, < 11.2.1≥ 11.1.0, < 11.1.5+3 more2025-04-11
CVE-2025-0124 [LOW] CWE-73 CVE-2025-0124: An authenticated file deletion vulnerability in the Palo Alto Networks PAN-OS® software enables an a
An authenticated file deletion vulnerability in the Palo Alto Networks PAN-OS® software enables an authenticated attacker with network access to the management web interface to delete certain files as the “nobody” user; this includes limited logs and configuration files but does not include system files.
The attacker must have network access to the manag
nvd
CVE-2026-0308P4LOWCVSS 1.1≥ 12.1.0, < 12.1.10≥ 11.2.0, < 11.2.13-h2+1 more2026-09-10
CVE-2026-0308 [LOW] CWE-79 CVE-2026-0308: A stored cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS® software enables a m
A stored cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS® software enables a malicious authenticated administrator to store or execute a JavaScript payload using the web interface.
This issue is applicable to PAN-OS software on PA-Series and VM-Series firewalls and on Panorama (virtual and M-Series).
Cloud NGFW and Prisma® Access a
nvd
CVE-2026-0228P4LOWCVSS 1.3≥ 11.2.0, < 11.2.8≥ 11.1.0, < 11.1.11+1 more2026-02-11
CVE-2026-0228 [LOW] CWE-295 CVE-2026-0228: An improper certificate validation vulnerability in PAN-OS allows users to connect Terminal Server A
An improper certificate validation vulnerability in PAN-OS allows users to connect Terminal Server Agents on Windows to PAN-OS using expired certificates even if the PAN-OS configuration would not normally permit them to do so.
nvd
CVE-2021-3047P4LOWCVSS 3.1≥ 8.1, < 8.1.19≥ 9.0, < 9.0.14+2 more2021-08-11
CVE-2021-3047 [LOW] CWE-338 CVE-2021-3047: A cryptographically weak pseudo-random number generator (PRNG) is used during authentication to the
A cryptographically weak pseudo-random number generator (PRNG) is used during authentication to the Palo Alto Networks PAN-OS web interface. This enables an authenticated attacker, with the capability to observe their own authentication secrets over a long duration on the PAN-OS appliance, to impersonate another authenticated web interface administrator's
nvd
CVE-2020-2044P4LOWCVSS 3.3v8.0.*≥ 8.1, < 8.1.16+2 more2020-09-09
CVE-2020-2044 [LOW] CWE-532 CVE-2020-2044: An information exposure through log file vulnerability where an administrator's password or other se
An information exposure through log file vulnerability where an administrator's password or other sensitive information may be logged in cleartext while using the CLI in Palo Alto Networks PAN-OS software. The opcmdhistory.log file was introduced to track operational command (op-command) usage but did not mask all sensitive information. The opcmdhistory.
nvd
CVE-2020-2043P4LOWCVSS 3.3≥ 8.1, < 8.1.16≥ 9.0, < 9.0.10+1 more2020-09-09
CVE-2020-2043 [LOW] CWE-532 CVE-2020-2043: An information exposure through log file vulnerability where sensitive fields are recorded in the co
An information exposure through log file vulnerability where sensitive fields are recorded in the configuration log without masking on Palo Alto Networks PAN-OS software when the after-change-detail custom syslog field is enabled for configuration logs and the sensitive field appears multiple times in one log entry. The first instance of the sensitive fi
nvd
CVE-2020-2048P4LOWCVSS 3.3≥ 8.1, < 8.1.17≥ 9.0, < 9.0.11+1 more2020-11-12
CVE-2020-2048 [LOW] CWE-532 CVE-2020-2048: An information exposure through log file vulnerability exists where the password for the configured
An information exposure through log file vulnerability exists where the password for the configured system proxy server for a PAN-OS appliance may be displayed in cleartext when using the CLI in Palo Alto Networks PAN-OS software. This issue impacts: PAN-OS 8.1 versions earlier than PAN-OS 8.1.17; PAN-OS 9.0 versions earlier than PAN-OS 9.0.11; PAN-OS 9.1
nvd
CVE-2020-2035P4LOWCVSS 3.0v8.1.*v9.0.*+3 more2020-08-12
CVE-2020-2035 [LOW] CWE-20 CVE-2020-2035: When SSL/TLS Forward Proxy Decryption mode has been configured to decrypt the web transactions, the
When SSL/TLS Forward Proxy Decryption mode has been configured to decrypt the web transactions, the PAN-OS URL filtering feature inspects the HTTP Host and URL path headers for policy enforcement on the decrypted HTTPS web transactions but does not consider Server Name Indication (SNI) field within the TLS Client Hello handshake. This allows a compromised
nvd