Paloaltonetworks PAN-OS vulnerabilities

209 known vulnerabilities affecting paloaltonetworks/pan-os.

Total CVEs
209
CISA KEV
12
actively exploited
Public exploits
14
Exploited in wild
9
Severity breakdown
CRITICAL33HIGH75MEDIUM93LOW8

Vulnerabilities

Page 11 of 11
CVE-2012-6601CRITICALCVSS 10.0≤ 3.1.11v3.1.9+14 more2013-08-31
CVE-2012-6601 [CRITICAL] CWE-78 CVE-2012-6601: The device-management command-line interface in Palo Alto Networks PAN-OS before 3.1.12, 4.0.x befor The device-management command-line interface in Palo Alto Networks PAN-OS before 3.1.12, 4.0.x before 4.0.10, and 4.1.x before 4.1.4 allows remote attackers to execute arbitrary code via unspecified vectors, aka Ref ID 36983.
nvd
CVE-2012-6592CRITICALCVSS 10.0≤ 3.1.9v4.0.0+4 more2013-08-31
CVE-2012-6592 [CRITICAL] CWE-78 CVE-2012-6592: Palo Alto Networks PAN-OS before 3.1.10 and 4.0.x before 4.0.5 allows remote attackers to execute ar Palo Alto Networks PAN-OS before 3.1.10 and 4.0.x before 4.0.5 allows remote attackers to execute arbitrary commands via unspecified vectors, aka Ref ID 31091.
nvd
CVE-2012-6604CRITICALCVSS 9.0≤ 3.1.10v3.1.9+9 more2013-08-31
CVE-2012-6604 [CRITICAL] CWE-78 CVE-2012-6604: The device-management command-line interface in Palo Alto Networks PAN-OS before 3.1.11 and 4.0.x be The device-management command-line interface in Palo Alto Networks PAN-OS before 3.1.11 and 4.0.x before 4.0.9 allows remote authenticated users to execute arbitrary code via unspecified vectors, aka Ref ID 35249.
nvd
CVE-2012-6605CRITICALCVSS 9.0≤ 3.1.10v3.1.9+9 more2013-08-31
CVE-2012-6605 [CRITICAL] CWE-78 CVE-2012-6605: The device-management command-line interface in Palo Alto Networks PAN-OS before 3.1.11 and 4.0.x be The device-management command-line interface in Palo Alto Networks PAN-OS before 3.1.11 and 4.0.x before 4.0.9 allows remote authenticated users to execute arbitrary code via unspecified vectors, aka Ref ID 34896.
nvd
CVE-2013-5663MEDIUMCVSS 4.3≤ 4.0.8v4.0.0+21 more2013-08-31
CVE-2013-5663 [MEDIUM] CWE-264 CVE-2013-5663: The App-ID cache feature in Palo Alto Networks PAN-OS before 4.0.14, 4.1.x before 4.1.11, and 5.0.x The App-ID cache feature in Palo Alto Networks PAN-OS before 4.0.14, 4.1.x before 4.1.11, and 5.0.x before 5.0.2 allows remote attackers to bypass intended security policies via crafted requests that trigger invalid caching, as demonstrated by incorrect identification of HTTP traffic as SIP traffic, aka Ref ID 47195.
nvd
CVE-2012-6597MEDIUMCVSS 6.3≤ 3.1.10v3.1.9+9 more2013-08-31
CVE-2012-6597 [MEDIUM] CWE-20 CVE-2012-6597: Palo Alto Networks PAN-OS before 3.1.11 and 4.0.x before 4.0.9 allows remote authenticated users to Palo Alto Networks PAN-OS before 3.1.11 and 4.0.x before 4.0.9 allows remote authenticated users to cause a denial of service (management-server crash) by using the command-line interface for a crafted command, aka Ref ID 35254.
nvd
CVE-2012-6590MEDIUMCVSS 4.3v4.0.0v4.0.1+6 more2013-08-31
CVE-2012-6590 [MEDIUM] CWE-200 CVE-2012-6590: The web-based management UI in Palo Alto Networks PAN-OS 4.0.x before 4.0.8 allows remote attackers The web-based management UI in Palo Alto Networks PAN-OS 4.0.x before 4.0.8 allows remote attackers to obtain verbose error information via crafted input, aka Ref ID 33139.
nvd
CVE-2013-5664MEDIUMCVSS 4.3v4.0.0v4.0.1+27 more2013-08-31
CVE-2013-5664 [MEDIUM] CWE-79 CVE-2013-5664: Cross-site scripting (XSS) vulnerability in the web-based device-management API browser in Palo Alto Cross-site scripting (XSS) vulnerability in the web-based device-management API browser in Palo Alto Networks PAN-OS before 4.1.13 and 5.0.x before 5.0.6 allows remote attackers to inject arbitrary web script or HTML via crafted data, aka Ref ID 50908.
nvd
CVE-2012-6596MEDIUMCVSS 5.0v4.0.0v4.0.1+10 more2013-08-31
CVE-2012-6596 [MEDIUM] CWE-255 CVE-2012-6596: Palo Alto Networks PAN-OS 4.0.x before 4.0.9 and 4.1.x before 4.1.3 stores cleartext LDAP bind passw Palo Alto Networks PAN-OS 4.0.x before 4.0.9 and 4.1.x before 4.1.3 stores cleartext LDAP bind passwords in authd.log, which allows context-dependent attackers to obtain sensitive information by reading this file, aka Ref ID 35493.
nvd