Vulnerability index

Browse CVEs

301 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Pan Os CRITICAL 10.0
CVE-2020-2021 KEV

When Security Assertion Markup Language (SAML) authentication is enabled and the 'Validate Identity Provider Certificate' option is disabled (uncheck…

Fix: 8.1.15 / 9.0.9+
Fix from $2,300 2020-06-29
Pan Os HIGH 7.2
CVE-2020-2027

A buffer overflow vulnerability in the authd component of the PAN-OS management server allows authenticated administrators to disrupt system processe…

Fix: 8.1.13 / 9.0.7+
Fix from $1,950 2020-06-10
Pan Os HIGH 7.2
CVE-2020-2028

An OS Command Injection vulnerability in PAN-OS management server allows authenticated administrators to execute arbitrary OS commands with root priv…

Fix: 8.1.13 / 9.0.7+
Fix from $1,950 2020-06-10
Pan Os HIGH 7.2
CVE-2020-2029

An OS Command Injection vulnerability in the PAN-OS web management interface allows authenticated administrators to execute arbitrary OS commands wit…

Fix: 7.1.26 / 8.1.13+
Fix from $1,950 2020-06-10
Globalprotect HIGH 7.0
CVE-2020-2032

A race condition vulnerability Palo Alto Networks GlobalProtect app on Windows allows a local limited Windows user to execute programs with SYSTEM pr…

Fix: 5.0.10 / 5.1.4+
Fix from $1,950 2020-06-10
Globalprotect MEDIUM 5.3
CVE-2020-2033

When the pre-logon feature is enabled, a missing certification validation in Palo Alto Networks GlobalProtect app can disclose the pre-logon authenti…

Fix: 5.0.10 / 5.1.4+
Fix from $1,600 2020-06-10
Pan Os CRITICAL 9.0
CVE-2020-2018

An authentication bypass vulnerability in the Panorama context switching feature allows an attacker with network access to a Panorama's management in…

Fix: 7.1.26 / 8.1.12+
Fix from $2,300 2020-05-13
Pan Os HIGH 8.8
CVE-2020-2013

A cleartext transmission of sensitive information vulnerability in Palo Alto Networks PAN-OS Panorama that discloses an authenticated PAN-OS administ…

Fix: 8.1.13 / 9.0.6+
Fix from $1,950 2020-05-13
Pan Os HIGH 8.8
CVE-2020-2014

An OS Command Injection vulnerability in PAN-OS management server allows authenticated users to inject and execute arbitrary shell commands with root…

Fix: after 9.0.6
Fix from $1,950 2020-05-13
Pan Os HIGH 8.8
CVE-2020-2015

A buffer overflow vulnerability in the PAN-OS management server allows authenticated users to crash system processes or potentially execute arbitrary…

Fix: 7.1.26 / 8.1.13+
Fix from $1,950 2020-05-13
Pan Os HIGH 7.0
CVE-2020-2016

A race condition due to insecure creation of a file in a temporary directory vulnerability in PAN-OS allows for root privilege escalation from a limi…

Fix: 7.1.26 / 8.1.13+
Fix from $1,950 2020-05-13
Pan Os MEDIUM 6.1
CVE-2020-2017

A DOM-Based Cross Site Scripting Vulnerability exists in PAN-OS and Panorama Management Web Interfaces. A remote attacker able to convince an authent…

Fix: 7.1.26 / 8.1.13+
Fix from $1,600 2020-05-13
Pan Os HIGH 8.8
CVE-2020-2006

A stack-based buffer overflow vulnerability in the management server component of PAN-OS that allows an authenticated user to potentially execute arb…

Fix: after 8.1.13
Fix from $1,950 2020-05-13
Pan Os HIGH 7.5
CVE-2020-2011

An improper input validation vulnerability in the configuration daemon of Palo Alto Networks PAN-OS Panorama allows for a remote unauthenticated user…

Fix: 8.1.14 / 9.1.0+
Fix from $1,950 2020-05-13
Pan Os HIGH 7.5
CVE-2020-2012

Improper restriction of XML external entity reference ('XXE') vulnerability in Palo Alto Networks Panorama management service allows remote unauthent…

Fix: 8.1.13 / 9.0.7+
Fix from $1,950 2020-05-13
Pan Os HIGH 7.2
CVE-2020-2007

An OS command injection vulnerability in the management server component of PAN-OS allows an authenticated user to potentially execute arbitrary comm…

Fix: after 9.0.6
Fix from $1,950 2020-05-13
Pan Os HIGH 7.2
CVE-2020-2008

An OS command injection and external control of filename vulnerability in Palo Alto Networks PAN-OS allows authenticated administrators to execute co…

Fix: after 8.1.13
Fix from $1,950 2020-05-13
Pan Os HIGH 7.2
CVE-2020-2009

An external control of filename vulnerability in the SD WAN component of Palo Alto Networks PAN-OS Panorama allows an authenticated administrator to …

Fix: after 9.0.6
Fix from $1,950 2020-05-13
Pan Os HIGH 7.2
CVE-2020-2010

An OS command injection vulnerability in PAN-OS management interface allows an authenticated administrator to execute arbitrary OS commands with root…

Fix: after 9.0.6
Fix from $1,950 2020-05-13
Pan Os MEDIUM 6.5
CVE-2020-2003

An external control of filename vulnerability in the command processing of PAN-OS allows an authenticated administrator to delete arbitrary system fi…

Fix: 9.1.1+
Fix from $1,600 2020-05-13
Pan Os MEDIUM 6.1
CVE-2020-2005

A cross-site scripting (XSS) vulnerability exists when visiting malicious websites with the Palo Alto Networks GlobalProtect Clientless VPN that can …

Fix: 7.1.26 / 8.1.13+
Fix from $1,600 2020-05-13
Globalprotect MEDIUM 5.5
CVE-2020-2004

Under certain circumstances a user's password may be logged in cleartext in the PanGPS.log diagnostic file when logs are collected for troubleshootin…

Fix: 5.0.9 / 5.1.2+
Fix from $1,600 2020-05-13
Pan Os CRITICAL 9.8
CVE-2020-2001

An external control of path and data vulnerability in the Palo Alto Networks PAN-OS Panorama XSLT processing logic that allows an unauthenticated use…

Fix: 8.1.12 / 9.0.6+
Fix from $2,300 2020-05-13
Pan Os HIGH 8.8
CVE-2020-1998

An improper authorization vulnerability in PAN-OS that mistakenly uses the permissions of local linux users instead of the intended SAML permissions …

Fix: 7.1.26 / 8.1.13+
Fix from $1,950 2020-05-13
Pan Os HIGH 8.1
CVE-2020-2002

An authentication bypass by spoofing vulnerability exists in the authentication daemon and User-ID components of Palo Alto Networks PAN-OS by failing…

Fix: 7.1.26 / 8.1.13+
Fix from $1,950 2020-05-13
Pan Os MEDIUM 6.1
CVE-2020-1997

An open redirection vulnerability in the GlobalProtect component of Palo Alto Networks PAN-OS allows an attacker to specify an arbitrary redirection …

Fix: 7.1.26 / 8.0.14+
Fix from $1,600 2020-05-13
Pan Os MEDIUM 5.4
CVE-2020-1993

The GlobalProtect Portal feature in PAN-OS does not set a new session identifier after a successful user login, which allows session fixation attacks…

Fix: after 9.0.7
Fix from $1,600 2020-05-13
Pan Os MEDIUM 5.3
CVE-2020-1996

A missing authorization vulnerability in the management server component of PAN-OS Panorama allows a remote unauthenticated user to inject messages i…

Fix: after 9.0.8
Fix from $1,600 2020-05-13
Pan Os CRITICAL 9.8
CVE-2020-1992

A format string vulnerability in the Varrcvr daemon of PAN-OS on PA-7000 Series devices with a Log Forwarding Card (LFC) allows remote attackers to c…

Fix: 9.0.7 / 9.1.2+
Fix from $2,300 2020-04-08
Pan Os HIGH 7.2
CVE-2020-1990

A stack-based buffer overflow vulnerability in the management server component of PAN-OS allows an authenticated user to upload a corrupted PAN-OS co…

Fix: 8.1.13 / 9.0.7+
Fix from $1,950 2020-04-08