Palo Alto Networks PAN-OS是美国Palo Alto Networks公司的一套为其防火墙设备开发的操作系统。 Palo Alto Networks PAN-OS的Panorama上下文切换功能中存在授权问题漏洞。攻击者可通过网络访问Panorama管理界面利用该漏洞以较高的权限访问所管理的防火墙。以下产品及版本受到影响:Palo Alto Networks PAN-OS 7.1.26之前的7.1版本,8.1.12之前的8.1版本,9.0.0.6之前的9.0版本,8.0所有版本。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Palo Alto Networks | PAN-OS | 8.0.* | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2020-2014 | 8.8 HIGH | PAN-OS: OS injection vulnerability in PAN-OS management server |
| CVE-2020-2015 | 8.8 HIGH | PAN-OS: Buffer overflow in the management server |
| CVE-2020-2017 | 8.8 HIGH | PAN-OS: DOM-Based cross site scripting vulnerability in management web interface |
| CVE-2020-2013 | 8.3 HIGH | PAN-OS: Panorama context switch session cookie disclosure |
| CVE-2020-2002 | 8.1 HIGH | PAN-OS: Spoofed Kerberos key distribution center authentication bypass |
| CVE-2020-2001 | 8.1 HIGH | PAN-OS: Panorama External control of file vulnerability leads to privilege escalation |
| CVE-2020-2012 | 7.5 HIGH | PAN-OS: Panorama: XML external entity reference ('XXE') vulnerability leads the to informa |
| CVE-2020-2011 | 7.5 HIGH | PAN-OS: Panorama registration denial of service |
| CVE-2020-2010 | 7.2 HIGH | PAN-OS: Authenticated user command injection vulnerability |
| CVE-2020-2009 | 7.2 HIGH | PAN-OS: Panorama SD WAN arbitrary file creation |
| CVE-2020-2008 | 7.2 HIGH | PAN-OS: OS command injection or arbitrary file deletion vulnerability |
| CVE-2020-2007 | 7.2 HIGH | PAN-OS: OS command injection in management server |
| CVE-2020-2006 | 7.2 HIGH | PAN-OS: Buffer overflow in management server payload parser |
| CVE-2020-2005 | 7.1 HIGH | PAN-OS: GlobalProtect Clientless VPN session hijacking |
| CVE-2020-2016 | 7.0 HIGH | PAN-OS: Temporary file race condition vulnerability in PAN-OS leads to local privilege esc |
| CVE-2020-2004 | 6.8 MEDIUM | GlobalProtect App: Passwords may be logged in clear text while collecting troubleshooting |
| CVE-2020-2003 | 6.5 MEDIUM | PAN-OS: Authenticated administrator can delete arbitrary system file |
| CVE-2020-1998 | 5.4 MEDIUM | PAN-OS: Improper SAML SSO authorization of shared local users |
| CVE-2020-1997 | 5.3 MEDIUM | PAN-OS: GlobalProtect registration open redirect |
| CVE-2020-1996 | 5.3 MEDIUM | PAN-OS: Panorama management server log injection |
Showing top 20 of 24 CVEs. View all on vendor page → →
No comments yet