Paloalto Prisma Access vulnerabilities

104 known vulnerabilities affecting paloalto/prisma_access.

Total CVEs
104
CISA KEV
9
actively exploited
Public exploits
12
Exploited in wild
8
Severity breakdown
CRITICAL12HIGH39MEDIUM48LOW5

Vulnerabilities

Page 3 of 6
CVE-2023-38802HIGHCVSS 7.52023-09-13
CVE-2023-38802 [HIGH] CWE-754 PAN-OS: Denial-of-Service (DoS) Vulnerability in BGP Software PAN-OS: Denial-of-Service (DoS) Vulnerability in BGP Software BGP software such as FRRouting FRR included as part of the PAN-OS, Prisma SD-WAN ION, and Prisma Access routing features enable a remote attacker to incorrectly reset network sessions though an invalid BGP update. This issue is applicable only to devices and appliances with BGP routing features enabled. This issue requires the remote attacker
paloalto
CVE-2023-36671MEDIUMCVSS 5.72023-08-17
CVE-2023-36671 [MEDIUM] CWE-829 PAN-SA-2023-0004 Informational Bulletin: Impact of TunnelCrack Vulnerabilities (CVE-2023-36671, CVE-2023-36672, CVE-2023-35838, and CVE-2023-36673) PAN-SA-2023-0004 Informational Bulletin: Impact of TunnelCrack Vulnerabilities (CVE-2023-36671, CVE-2023-36672, CVE-2023-35838, and CVE-2023-36673) The Palo Alto Networks Product Security Assurance team is aware of the research publication that details a combination of attacks named "TunnelCrack". These are also refer
paloalto
CVE-2023-38046MEDIUMCVSS 4.92023-07-12
CVE-2023-38046 [MEDIUM] CWE-610 PAN-OS: Read System Files and Resources During Configuration Commit PAN-OS: Read System Files and Resources During Configuration Commit A vulnerability exists in Palo Alto Networks PAN-OS software that enables an authenticated administrator with the privilege to commit a specifically created configuration to read local files and resources from the system. Affected products: Cloud NGFW, PAN-OS, Prisma Access Solution: This issue is fixed in PAN-OS 10.2.4, PAN-OS
paloalto
CVE-2023-34362CRITICALCVSS 9.8KEVPoC2023-06-16
CVE-2023-34362 [CRITICAL] PAN-SA-2023-0003 Informational Bulletin: Impact of MOVEit Vulnerabilities (CVE-2023-34362, CVE-2023-35036, CVE-2023-35708) PAN-SA-2023-0003 Informational Bulletin: Impact of MOVEit Vulnerabilities (CVE-2023-34362, CVE-2023-35036, CVE-2023-35708) The Palo Alto Networks Product Security Assurance team has evaluated the recently disclosed critical Structured Query Language injection (SQLi) vulnerabilities (CVE-2023-34362, CVE-2023-35036, CVE-2023-35708) in the MOVEit Tran
paloalto
CVE-2023-0010MEDIUMCVSS 5.42023-06-14
CVE-2023-0010 [MEDIUM] CWE-79 PAN-OS: Reflected Cross-Site Scripting (XSS) Vulnerability in Captive Portal Authentication PAN-OS: Reflected Cross-Site Scripting (XSS) Vulnerability in Captive Portal Authentication A reflected cross-site scripting (XSS) vulnerability in the Captive Portal feature of Palo Alto Networks PAN-OS software can allow a JavaScript payload to be executed in the context of an authenticated Captive Portal user’s browser when they click on a specifically crafted link. Aff
paloalto
CVE-2023-0007MEDIUMCVSS 4.82023-05-10
CVE-2023-0007 [MEDIUM] CWE-80 PAN-OS: Stored Cross-Site Scripting (XSS) Vulnerability in the Panorama Web Interface PAN-OS: Stored Cross-Site Scripting (XSS) Vulnerability in the Panorama Web Interface A cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS software on Panorama appliances enables an authenticated read-write administrator to store a JavaScript payload in the web interface that will execute in the context of another administrator’s browser when viewed. Affected p
paloalto
CVE-2023-0008MEDIUMCVSS 4.42023-05-10
CVE-2023-0008 [MEDIUM] CWE-73 PAN-OS: Local File Disclosure Vulnerability in the PAN-OS Web Interface PAN-OS: Local File Disclosure Vulnerability in the PAN-OS Web Interface A file disclosure vulnerability in Palo Alto Networks PAN-OS software enables an authenticated read-write administrator with access to the web interface to export local files from the firewall through a race condition. Affected products: Cloud NGFW, PAN-OS, Prisma Access Solution: This issue is fixed in PAN-OS 8.1.25, PAN
paloalto
CVE-2023-0005MEDIUMCVSS 4.92023-04-12
CVE-2023-0005 [MEDIUM] CWE-497 PAN-OS: Exposure of Sensitive Information Vulnerability PAN-OS: Exposure of Sensitive Information Vulnerability A vulnerability in Palo Alto Networks PAN-OS software enables an authenticated administrator to expose the plaintext values of secrets stored in the device configuration and encrypted API keys. Affected products: Cloud NGFW, PAN-OS, Prisma Access Solution: This issue is fixed in PAN-OS 8.1.24, PAN-OS 9.0.17, PAN-OS 9.1.15, PAN-OS 10.0.12, PAN-OS 10.1.8
paloalto
CVE-2023-0004MEDIUMCVSS 6.52023-04-12
CVE-2023-0004 [MEDIUM] CWE-703 PAN-OS: Local File Deletion Vulnerability PAN-OS: Local File Deletion Vulnerability A local file deletion vulnerability in Palo Alto Networks PAN-OS software enables an authenticated administrator to delete files from the local file system with elevated privileges. These files can include logs and system components that impact the integrity and availability of PAN-OS software. Affected products: Cloud NGFW, PAN-OS, Prisma Access Solution: This issue is fixed in
paloalto
CVE-2023-22809HIGHCVSS 7.8PoC2023-02-08
CVE-2023-22809 [HIGH] Impact of Sudo Vulnerability CVE-2023-22809 Impact of Sudo Vulnerability CVE-2023-22809 The Palo Alto Networks Product Security Assurance team has evaluated the sudo software vulnerability CVE-2023-22809 and has determined that the following Palo Alto Networks products do not expose the sudo program and, therefore, do not offer any scenarios required for successful exploitation of this vulnerability. Affected products: Cloud NGFW, PAN-OS, Prisma Access, Prisma SD-WAN ION
paloalto
CVE-2023-0286MEDIUMCVSS 4.92023-02-08
CVE-2023-0286 [MEDIUM] PAN-SA-2023-0001 Impact of OpenSSL Vulnerabilities Disclosed Feb 7, 2023 PAN-SA-2023-0001 Impact of OpenSSL Vulnerabilities Disclosed Feb 7, 2023 The Palo Alto Networks Product Security Assurance team has evaluated the OpenSSL vulnerabilities that were disclosed on February 7, 2023 (CVE-2023-0286, CVE-2022-4304, CVE-2022-4203, CVE-2023-0215, CVE-2022-4450, CVE-2023-0216, CVE-2023-0217, and CVE-2023-0401) as it relates to our products. At this time, there are no demonstrat
paloalto
CVE-2022-3996HIGHCVSS 7.52022-12-23
CVE-2022-3996 [HIGH] CWE-667 PAN-SA-2022-0007 Impact of OpenSSL 3.0 Vulnerability CVE-2022-3996 PAN-SA-2022-0007 Impact of OpenSSL 3.0 Vulnerability CVE-2022-3996 The OpenSSL Project has published a vulnerability CVE-2022-3996 that affects OpenSSL versions 3.0.0 through 3.0.7 on December 13, 2022. CVEs: CVE-2022-3996 Affected products: Cortex Data, Cortex XDR, Cortex XSOAR, Cortex Xpanse, GlobalProtect, PAN-OS, Prisma Access, Prisma Cloud, Prisma SD
paloalto
CVE-2022-42889CRITICALCVSS 9.8ExploitedPoC2022-11-09
CVE-2022-42889 [CRITICAL] CWE-94 CVE-2022-42889 Impact of Apache Text Commons Vulnerability CVE-2022-42889 CVE-2022-42889 Impact of Apache Text Commons Vulnerability CVE-2022-42889 Palo Alto Networks has evaluated the Apache Commons Text library vulnerability CVE-2022-42889, known as Text4Shell, for all products and services. The Palo Alto Networks Product Security Assurance team has confirmed that all products and services are not impacted by this vulnerability. CVE Summary CVE-2022-42889 Apac
paloalto
CVE-2022-3786HIGHCVSS 7.52022-10-31
CVE-2022-3786 [HIGH] PAN-SA-2022-0006 Impact of OpenSSL 3.0 Vulnerabilities CVE-2022-3786 and CVE-2022-3602 PAN-SA-2022-0006 Impact of OpenSSL 3.0 Vulnerabilities CVE-2022-3786 and CVE-2022-3602 The OpenSSL Project has published two high CVEs: CVE-2022-3602, CVE-2022-3786 Affected products: Cortex Data, Cortex XDR, Cortex XSOAR, Cortex Xpanse, GlobalProtect, PAN-OS, Prisma Access, Prisma Cloud, Prisma SD
paloalto
CVE-2022-0030HIGHCVSS 8.12022-10-12
CVE-2022-0030 [HIGH] CWE-290 PAN-OS: Authentication Bypass in Web Interface PAN-OS: Authentication Bypass in Web Interface An authentication bypass vulnerability in the Palo Alto Networks PAN-OS 8.1 web interface allows a network-based attacker with specific knowledge of the target firewall or Panorama appliance to impersonate an existing PAN-OS administrator and perform privileged actions. Affected products: Cloud NGFW, PAN-OS, Prisma Access Solution: This issue is fixed in PAN-OS 8.1.24 and
paloalto
CVE-2022-28199HIGHCVSS 8.62022-09-14
CVE-2022-28199 [HIGH] CWE-20 Informational: PAN-OS: Impact of the NVIDIA Dataplane Development Kit (DPDK) Vulnerability CVE-2022-28199 Informational: PAN-OS: Impact of the NVIDIA Dataplane Development Kit (DPDK) Vulnerability CVE-2022-28199 The Palo Alto Networks Product Security Assurance team evaluated the NVIDIA Dataplane Development Kit (DPDK) vulnerability (CVE-2022-28199) as it relates to our products. This vulnerability causes networking stacks that use the NVIDIA distribution of the DP
paloalto
CVE-2022-0028HIGHCVSS 8.6KEV2022-08-10
CVE-2022-0028 [HIGH] CWE-406 PAN-OS: Reflected Amplification Denial-of-Service (DoS) Vulnerability in URL Filtering PAN-OS: Reflected Amplification Denial-of-Service (DoS) Vulnerability in URL Filtering A PAN-OS URL filtering policy misconfiguration could allow a network-based attacker to conduct reflected and amplified TCP denial-of-service (RDoS) attacks. The DoS attack would appear to originate from a Palo Alto Networks PA-Series (hardware), VM-Series (virtual) and CN-Series (container) fire
paloalto
CVE-2022-0023MEDIUMCVSS 5.92022-04-13
CVE-2022-0023 [MEDIUM] CWE-755 PAN-OS: Denial-of-Service (DoS) Vulnerability in DNS Proxy PAN-OS: Denial-of-Service (DoS) Vulnerability in DNS Proxy An improper handling of exceptional conditions vulnerability exists in the DNS proxy feature of Palo Alto Networks PAN-OS software that enables a meddler-in-the-middle (MITM) to send specifically crafted traffic to the firewall that causes the service to restart unexpectedly. Repeated attempts to send this request result in denial-of-service to all
paloalto
CVE-2022-0778HIGHCVSS 7.52022-03-31
CVE-2022-0778 [HIGH] CWE-834 Impact of the OpenSSL Infinite Loop Vulnerability CVE-2022-0778 Impact of the OpenSSL Infinite Loop Vulnerability CVE-2022-0778 The Palo Alto Networks Product Security Assurance team has evaluated the OpenSSL infinite loop vulnerability (CVE-2022-0778) as it relates to our products. This vulnerability causes the OpenSSL library to enter an infinite loop when parsing an invalid certificate and can result in a Denial-of-Service (DoS) to the application. An attacker d
paloalto
CVE-2021-44142HIGHCVSS 8.82022-03-09
CVE-2021-44142 [HIGH] CWE-125 Informational: Impact of the Samba Vulnerability CVE-2021-44142 on PAN-OS Informational: Impact of the Samba Vulnerability CVE-2021-44142 on PAN-OS The Palo Alto Networks Product Security Assurance team has evaluated the Samba CVE-2021-44142 vulnerability. Though PAN-OS software contains Samba packages, there isn’t a Samba server that runs in PAN-OS software that could enable an attacker to exploit this vulnerability, which means there are no scenarios that enable
paloalto