Palo Alto Networks PAN-OS是美国Palo Alto Networks公司的一套为其防火墙设备开发的操作系统。 Palo Alto Networks PAN-OS 7.1版本、8.0版本和8.1.14之前的8.1版本的管理服务器组件中存在缓冲区错误漏洞。攻击者可利用该漏洞以root权限执行任意代码。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Palo Alto Networks | PAN-OS | 7.1.* | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2020-2018 | 9.0 CRITICAL | PAN-OS: Panorama authentication bypass vulnerability |
| CVE-2020-2014 | 8.8 HIGH | PAN-OS: OS injection vulnerability in PAN-OS management server |
| CVE-2020-2015 | 8.8 HIGH | PAN-OS: Buffer overflow in the management server |
| CVE-2020-2017 | 8.8 HIGH | PAN-OS: DOM-Based cross site scripting vulnerability in management web interface |
| CVE-2020-2013 | 8.3 HIGH | PAN-OS: Panorama context switch session cookie disclosure |
| CVE-2020-2002 | 8.1 HIGH | PAN-OS: Spoofed Kerberos key distribution center authentication bypass |
| CVE-2020-2001 | 8.1 HIGH | PAN-OS: Panorama External control of file vulnerability leads to privilege escalation |
| CVE-2020-2012 | 7.5 HIGH | PAN-OS: Panorama: XML external entity reference ('XXE') vulnerability leads the to informa |
| CVE-2020-2011 | 7.5 HIGH | PAN-OS: Panorama registration denial of service |
| CVE-2020-2010 | 7.2 HIGH | PAN-OS: Authenticated user command injection vulnerability |
| CVE-2020-2009 | 7.2 HIGH | PAN-OS: Panorama SD WAN arbitrary file creation |
| CVE-2020-2008 | 7.2 HIGH | PAN-OS: OS command injection or arbitrary file deletion vulnerability |
| CVE-2020-2007 | 7.2 HIGH | PAN-OS: OS command injection in management server |
| CVE-2020-2005 | 7.1 HIGH | PAN-OS: GlobalProtect Clientless VPN session hijacking |
| CVE-2020-2016 | 7.0 HIGH | PAN-OS: Temporary file race condition vulnerability in PAN-OS leads to local privilege esc |
| CVE-2020-2004 | 6.8 MEDIUM | GlobalProtect App: Passwords may be logged in clear text while collecting troubleshooting |
| CVE-2020-2003 | 6.5 MEDIUM | PAN-OS: Authenticated administrator can delete arbitrary system file |
| CVE-2020-1998 | 5.4 MEDIUM | PAN-OS: Improper SAML SSO authorization of shared local users |
| CVE-2020-1997 | 5.3 MEDIUM | PAN-OS: GlobalProtect registration open redirect |
| CVE-2020-1996 | 5.3 MEDIUM | PAN-OS: Panorama management server log injection |
Showing top 20 of 24 CVEs. View all on vendor page → →
No comments yet