Paloalto Globalprotect vulnerabilities
10 known vulnerabilities affecting paloalto/globalprotect.
Total CVEs
10
CISA KEV
2
actively exploited
Public exploits
3
Exploited in wild
3
Severity breakdown
CRITICAL3HIGH3MEDIUM3LOW1
Vulnerabilities
Page 1 of 1
CVE-2024-9474CRITICALCVSS 9.3KEVPoC2024-11-18
CVE-2024-9474 [CRITICAL] CWE-306 PAN-SA-2024-0015 PAN-OS: Authentication Bypass in the Management Web Interface (PAN-SA-2024-0015)
PAN-SA-2024-0015 PAN-OS: Authentication Bypass in the Management Web Interface (PAN-SA-2024-0015)
An authentication bypass in Palo Alto Networks PAN-OS software enables an unauthenticated attacker with network access to the management web interface to gain PAN-OS administrator privileges to perform administrative actions, tamper with the configuration, or exploit ot
paloalto
CVE-2023-36671MEDIUMCVSS 5.72023-08-17
CVE-2023-36671 [MEDIUM] CWE-829 PAN-SA-2023-0004 Informational Bulletin: Impact of TunnelCrack Vulnerabilities (CVE-2023-36671, CVE-2023-36672, CVE-2023-35838, and CVE-2023-36673)
PAN-SA-2023-0004 Informational Bulletin: Impact of TunnelCrack Vulnerabilities (CVE-2023-36671, CVE-2023-36672, CVE-2023-35838, and CVE-2023-36673)
The Palo Alto Networks Product Security Assurance team is aware of the research publication that details a combination of attacks named "TunnelCrack". These are also refer
paloalto
CVE-2023-34362CRITICALCVSS 9.8KEVPoC2023-06-16
CVE-2023-34362 [CRITICAL] PAN-SA-2023-0003 Informational Bulletin: Impact of MOVEit Vulnerabilities (CVE-2023-34362, CVE-2023-35036, CVE-2023-35708)
PAN-SA-2023-0003 Informational Bulletin: Impact of MOVEit Vulnerabilities (CVE-2023-34362, CVE-2023-35036, CVE-2023-35708)
The Palo Alto Networks Product Security Assurance team has evaluated the recently disclosed critical Structured Query Language injection (SQLi) vulnerabilities (CVE-2023-34362, CVE-2023-35036, CVE-2023-35708) in the MOVEit Tran
paloalto
CVE-2023-0286MEDIUMCVSS 4.92023-02-08
CVE-2023-0286 [MEDIUM] PAN-SA-2023-0001 Impact of OpenSSL Vulnerabilities Disclosed Feb 7, 2023
PAN-SA-2023-0001 Impact of OpenSSL Vulnerabilities Disclosed Feb 7, 2023
The Palo Alto Networks Product Security Assurance team has evaluated the OpenSSL vulnerabilities that were disclosed on February 7, 2023 (CVE-2023-0286, CVE-2022-4304, CVE-2022-4203, CVE-2023-0215, CVE-2022-4450, CVE-2023-0216, CVE-2023-0217, and CVE-2023-0401) as it relates to our products. At this time, there are no demonstrat
paloalto
CVE-2022-3996HIGHCVSS 7.52022-12-23
CVE-2022-3996 [HIGH] CWE-667 PAN-SA-2022-0007 Impact of OpenSSL 3.0 Vulnerability CVE-2022-3996
PAN-SA-2022-0007 Impact of OpenSSL 3.0 Vulnerability CVE-2022-3996
The OpenSSL Project has published a vulnerability CVE-2022-3996 that affects OpenSSL versions 3.0.0 through 3.0.7 on December 13, 2022.
CVEs: CVE-2022-3996
Affected products: Cortex Data, Cortex XDR, Cortex XSOAR, Cortex Xpanse, GlobalProtect, PAN-OS, Prisma Access, Prisma Cloud, Prisma SD
paloalto
CVE-2022-42889CRITICALCVSS 9.8ExploitedPoC2022-11-09
CVE-2022-42889 [CRITICAL] CWE-94 CVE-2022-42889 Impact of Apache Text Commons Vulnerability CVE-2022-42889
CVE-2022-42889 Impact of Apache Text Commons Vulnerability CVE-2022-42889
Palo Alto Networks has evaluated the Apache Commons Text library vulnerability CVE-2022-42889, known as Text4Shell, for all products and services. The Palo Alto Networks Product Security Assurance team has confirmed that all products and services are not impacted by this vulnerability. CVE Summary CVE-2022-42889 Apac
paloalto
CVE-2022-3786HIGHCVSS 7.52022-10-31
CVE-2022-3786 [HIGH] PAN-SA-2022-0006 Impact of OpenSSL 3.0 Vulnerabilities CVE-2022-3786 and CVE-2022-3602
PAN-SA-2022-0006 Impact of OpenSSL 3.0 Vulnerabilities CVE-2022-3786 and CVE-2022-3602
The OpenSSL Project has published two high
CVEs: CVE-2022-3602, CVE-2022-3786
Affected products: Cortex Data, Cortex XDR, Cortex XSOAR, Cortex Xpanse, GlobalProtect, PAN-OS, Prisma Access, Prisma Cloud, Prisma SD
paloalto
CVE-2020-1971MEDIUMCVSS 5.92020-12-09
CVE-2020-1971 [MEDIUM] PAN-SA-2020-0011 Informational: Impact of OpenSSL vulnerability CVE-2020-1971
PAN-SA-2020-0011 Informational: Impact of OpenSSL vulnerability CVE-2020-1971
Palo Alto Networks Product Security Assurance team has evaluated the vulnerability CVE-2020-1971 that affects the OpenSSL library. The vulnerability does not have a security impact on PAN-OS, GlobalProtect App, or Cortex XSOAR. The scenarios required for successful
CVEs: CVE-2020-1971
Affected products: Cortex XSOAR,
paloalto
CVE-2019-11477HIGHCVSS 7.52019-06-27
CVE-2019-11477 [HIGH] CWE-190 PAN-SA-2019-0013 Information about TCP SACK Panic Findings in PAN-OS
PAN-SA-2019-0013 Information about TCP SACK Panic Findings in PAN-OS
Palo Alto Networks is aware of recent vulnerability disclosures known as TCP SACK Panic vulnerabilities. (Ref: PAN-119745/ CVE-2019-11477, CVE-2019-11478, CVE-2019-11479) Successful
CVEs: CVE-2019-11477, CVE-2019-11478, CVE-2019-11479, CVE-2019-5599
Affected products: GlobalProtect, PAN-OS
paloalto
CVE-2013-0169LOWCVSS 2.62016-09-02
CVE-2013-0169 [LOW] CWE-119 PAN-SA-2016-0023 OpenSSL Vulnerabilities
PAN-SA-2016-0023 OpenSSL Vulnerabilities
The OpenSSL library embedded in the GlobalProtect™ agent, TerminalServer™ agent and UserID™ agent is
CVEs: CVE-2013-0169, CVE-2016-2105, CVE-2016-2106, CVE-2016-2107, CVE-2016-2109, CVE-2016-2176
Affected products: GlobalProtect
paloalto