Paloaltonetworks PAN-OS vulnerabilities

209 known vulnerabilities affecting paloaltonetworks/pan-os.

Total CVEs
209
CISA KEV
12
actively exploited
Public exploits
14
Exploited in wild
9
Severity breakdown
CRITICAL33HIGH75MEDIUM93LOW8

Vulnerabilities

Page 9 of 11
CVE-2017-15940CRITICALCVSS 9.8fixed in 6.1.19≥ 7.0.0, < 7.0.19+2 more2017-12-11
CVE-2017-15940 [CRITICAL] CWE-77 CVE-2017-15940: The web interface packet capture management component in Palo Alto Networks PAN-OS before 6.1.19, 7. The web interface packet capture management component in Palo Alto Networks PAN-OS before 6.1.19, 7.0.x before 7.0.19, 7.1.x before 7.1.14, and 8.0.x before 8.0.6 allows remote authenticated users to execute arbitrary code via unspecified vectors.
nvd
CVE-2017-15942HIGHCVSS 7.5fixed in 6.1.19≥ 7.0.0, < 7.0.19+2 more2017-12-11
CVE-2017-15942 [HIGH] CVE-2017-15942: Palo Alto Networks PAN-OS before 6.1.19, 7.0.x before 7.0.19, 7.1.x before 7.1.13, and 8.0.x before Palo Alto Networks PAN-OS before 6.1.19, 7.0.x before 7.0.19, 7.1.x before 7.1.13, and 8.0.x before 8.0.6 allows remote attackers to cause a denial of service via vectors related to the management interface.
nvd
CVE-2017-15943MEDIUMCVSS 5.3fixed in 6.1.19≥ 7.0.0, < 7.0.19+1 more2017-12-11
CVE-2017-15943 [MEDIUM] CWE-918 CVE-2017-15943: The configuration file import for applications, spyware and vulnerability objects functionality in t The configuration file import for applications, spyware and vulnerability objects functionality in the web interface in Palo Alto Networks PAN-OS before 6.1.19, 7.0.x before 7.0.19, and 7.1.x before 7.1.14 allows remote attackers to conduct server-side request forgery (SSRF) attacks and consequently obtain sensitive information via vectors related t
nvd
CVE-2016-8610HIGHCVSS 7.5≤ 6.1.17≥ 7.0.0, ≤ 7.0.15+1 more2017-11-13
CVE-2016-8610 [HIGH] CWE-400 CVE-2016-8610: A denial of service flaw was found in OpenSSL 0.9.8, 1.0.1, 1.0.2 through 1.0.2h, and 1.1.0 in the w A denial of service flaw was found in OpenSSL 0.9.8, 1.0.1, 1.0.2 through 1.0.2h, and 1.1.0 in the way the TLS/SSL protocol defined processing of ALERT packets during a connection handshake. A remote attacker could use this flaw to make a TLS/SSL server consume an excessive amount of CPU and fail to accept connections from other clients.
nvd
CVE-2017-9458CRITICALCVSS 9.8≤ 6.1.17v7.0.0+27 more2017-09-07
CVE-2017-9458 [CRITICAL] CWE-611 CVE-2017-9458: XML external entity (XXE) vulnerability in the GlobalProtect internal and external gateway interface XML external entity (XXE) vulnerability in the GlobalProtect internal and external gateway interface in Palo Alto Networks PAN-OS before 6.1.18, 7.0.x before 7.0.17, 7.1.x before 7.1.12, and 8.0.x before 8.0.3 allows remote attackers to obtain sensitive information, cause a denial of service, or conduct server-side request forgery (SSRF) attacks via
nvd
CVE-2017-12416MEDIUMCVSS 6.1≤ 6.1.17v7.0.0+27 more2017-09-07
CVE-2017-12416 [MEDIUM] CWE-79 CVE-2017-12416: Cross-site scripting (XSS) vulnerability in the GlobalProtect internal and external gateway interfac Cross-site scripting (XSS) vulnerability in the GlobalProtect internal and external gateway interface in Palo Alto Networks PAN-OS before 6.1.18, 7.0.x before 7.0.17, 7.1.x before 7.1.12, and 8.0.x before 8.0.3 allows remote attackers to inject arbitrary web script or HTML via vectors related to improper request parameter validation.
nvd
CVE-2017-8390CRITICALCVSS 9.8≤ 6.1.17v7.0.1+29 more2017-08-02
CVE-2017-8390 [CRITICAL] CWE-20 CVE-2017-8390: The DNS Proxy in Palo Alto Networks PAN-OS before 6.1.18, 7.x before 7.0.16, 7.1.x before 7.1.11, an The DNS Proxy in Palo Alto Networks PAN-OS before 6.1.18, 7.x before 7.0.16, 7.1.x before 7.1.11, and 8.x before 8.0.3 allows remote attackers to execute arbitrary code via a crafted domain name.
nvd
CVE-2017-9459MEDIUMCVSS 6.1≤ 6.1.17v7.0.1+29 more2017-08-02
CVE-2017-9459 [MEDIUM] CWE-79 CVE-2017-9459: Cross-site scripting (XSS) vulnerability in the management web interface in Palo Alto Networks PAN-O Cross-site scripting (XSS) vulnerability in the management web interface in Palo Alto Networks PAN-OS before 6.1.18, 7.x before 7.0.16, 7.1.x before 7.1.11, and 8.x before 8.0.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
nvd
CVE-2017-9467MEDIUMCVSS 6.1≤ 6.1.17v7.0.1+28 more2017-08-02
CVE-2017-9467 [MEDIUM] CWE-79 CVE-2017-9467: Cross-site scripting (XSS) vulnerability in the GlobalProtect external interface in Palo Alto Networ Cross-site scripting (XSS) vulnerability in the GlobalProtect external interface in Palo Alto Networks PAN-OS before 6.1.18, 7.x before 7.0.16, 7.1.x before 7.1.11, and 8.x before 8.0.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
nvd
CVE-2015-6531HIGHCVSS 7.8≤ 6.02017-06-01
CVE-2015-6531 [HIGH] CWE-94 CVE-2015-6531: Palo Alto Networks Panorama VM Appliance with PAN-OS before 6.0.1 might allow remote attackers to ex Palo Alto Networks Panorama VM Appliance with PAN-OS before 6.0.1 might allow remote attackers to execute arbitrary Python code via a crafted firmware image file.
nvd
CVE-2017-7216MEDIUMCVSS 6.5≤ 7.1.82017-05-02
CVE-2017-7216 [MEDIUM] CWE-200 CVE-2017-7216: The Management Web Interface in Palo Alto Networks PAN-OS before 7.1.9 allows remote authenticated u The Management Web Interface in Palo Alto Networks PAN-OS before 7.1.9 allows remote authenticated users to obtain sensitive information via unspecified request parameters.
nvd
CVE-2017-7945CRITICALCVSS 9.8≤ 6.1.15v7.0.0+25 more2017-04-29
CVE-2017-7945 [CRITICAL] CWE-209 CVE-2017-7945: The GlobalProtect external interface in Palo Alto Networks PAN-OS before 6.1.17, 7.x before 7.0.15, The GlobalProtect external interface in Palo Alto Networks PAN-OS before 6.1.17, 7.x before 7.0.15, 7.1.x before 7.1.9, and 8.x before 8.0.2 provides different error messages for failed login attempts depending on whether the username exists, which allows remote attackers to enumerate account names and conduct brute-force attacks via a series of requ
nvd
CVE-2017-7644MEDIUMCVSS 6.5≤ 6.1.15v7.0.0+23 more2017-04-29
CVE-2017-7644 [MEDIUM] CWE-200 CVE-2017-7644: The Management Web Interface in Palo Alto Networks PAN-OS before 6.1.17, 7.x before 7.0.15, and 7.1. The Management Web Interface in Palo Alto Networks PAN-OS before 6.1.17, 7.x before 7.0.15, and 7.1.x before 7.1.9 allows remote authenticated users to obtain sensitive information by leveraging incorrect permission validation, aka PAN-SA-2017-0013 and PAN-70541.
nvd
CVE-2017-7409MEDIUMCVSS 6.1≤ 7.0.142017-04-21
CVE-2017-7409 [MEDIUM] CWE-79 CVE-2017-7409: Palo Alto Networks PAN-OS before 7.0.15 has XSS in the GlobalProtect external interface via crafted Palo Alto Networks PAN-OS before 7.0.15 has XSS in the GlobalProtect external interface via crafted request parameters, aka PAN-SA-2017-0011 and PAN-70674.
nvd
CVE-2017-7218HIGHCVSS 7.8≤ 7.1.82017-04-14
CVE-2017-7218 [HIGH] CWE-20 CVE-2017-7218: The Management Web Interface in Palo Alto Networks PAN-OS before 7.1.9 allows remote authenticated u The Management Web Interface in Palo Alto Networks PAN-OS before 7.1.9 allows remote authenticated users to gain privileges via unspecified request parameters.
nvd
CVE-2017-7217MEDIUMCVSS 4.3≤ 7.0.13v7.1.0+9 more2017-04-14
CVE-2017-7217 [MEDIUM] CWE-20 CVE-2017-7217: The Management Web Interface in Palo Alto Networks PAN-OS before 7.0.14 and 7.1.x before 7.1.9 allow The Management Web Interface in Palo Alto Networks PAN-OS before 7.0.14 and 7.1.x before 7.1.9 allows remote attackers to write to export files via unspecified parameters.
nvd
CVE-2017-5584MEDIUMCVSS 5.4v5.1v6.0+50 more2017-03-15
CVE-2017-5584 [MEDIUM] CWE-79 CVE-2017-5584: Cross-site scripting (XSS) vulnerability in the Management Web Interface in Palo Alto Networks PAN-O Cross-site scripting (XSS) vulnerability in the Management Web Interface in Palo Alto Networks PAN-OS 5.1, 6.x before 6.1.16, 7.0.x before 7.0.13, and 7.1.x before 7.1.8 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
nvd
CVE-2017-5583MEDIUMCVSS 6.5≤ 6.1.15v7.0.1+21 more2017-03-15
CVE-2017-5583 [MEDIUM] CWE-200 CVE-2017-5583: The Management Web Interface in Palo Alto Networks PAN-OS before 6.1.16, 7.0.x before 7.0.13, and 7. The Management Web Interface in Palo Alto Networks PAN-OS before 6.1.16, 7.0.x before 7.0.13, and 7.1.x before 7.1.8 allows remote authenticated users to read arbitrary files via unspecified vectors.
nvd
CVE-2016-9150CRITICALCVSS 9.8PoC≥ 5.0.0, < 5.0.20≥ 5.1, < 5.1.13+4 more2016-11-19
CVE-2016-9150 [CRITICAL] CWE-119 CVE-2016-9150: Buffer overflow in the management web interface in Palo Alto Networks PAN-OS before 5.0.20, 5.1.x be Buffer overflow in the management web interface in Palo Alto Networks PAN-OS before 5.0.20, 5.1.x before 5.1.13, 6.0.x before 6.0.15, 6.1.x before 6.1.15, 7.0.x before 7.0.11, and 7.1.x before 7.1.6 allows remote attackers to execute arbitrary code via unspecified vectors.
nvd
CVE-2016-9151HIGHCVSS 7.8PoC≥ 5.0.0, < 5.0.20≥ 5.1, < 5.1.13+4 more2016-11-19
CVE-2016-9151 [HIGH] CWE-264 CVE-2016-9151: Palo Alto Networks PAN-OS before 5.0.20, 5.1.x before 5.1.13, 6.0.x before 6.0.15, 6.1.x before 6.1. Palo Alto Networks PAN-OS before 5.0.20, 5.1.x before 5.1.13, 6.0.x before 6.0.15, 6.1.x before 6.1.15, 7.0.x before 7.0.11, and 7.1.x before 7.1.6 allows local users to gain privileges via crafted values of unspecified environment variables.
nvd