Palo Alto Networks GlobalProtect是美国Palo Alto Networks公司的一套网络防护软件。该软件可提供防火墙监控及威胁预防等功能。 Palo Alto Networks GlobalProtect portal and gateway存在安全漏洞,攻击者可利用该漏洞向GlobalProtect接口发送特制的流量,从而导致服务停止响应。受影响的系统包括:PAN-OS 8.1.21之前的PAN-OS 8.1版本;PAN-OS 9.0.14-h4之前的PAN-OS 9.0
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Palo Alto Networks | PAN-OS | 8.1 ~ 8.1.21 | - |
|
| Palo Alto Networks | Prisma Access | 2.2 all | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2021-3064 | 9.8 CRITICAL | PAN-OS: Memory Corruption Vulnerability in GlobalProtect Portal and Gateway Interfaces |
| CVE-2021-3058 | 8.8 HIGH | PAN-OS: OS Command Injection Vulnerability in Web Interface XML API |
| CVE-2021-3056 | 8.8 HIGH | PAN-OS: Memory Corruption Vulnerability in GlobalProtect Clientless VPN During SAML Authen |
| CVE-2021-3062 | 8.1 HIGH | PAN-OS: Improper Access Control Vulnerability Exposing AWS Instance Metadata Endpoint to G |
| CVE-2021-3060 | 8.1 HIGH | PAN-OS: OS Command Injection in Simple Certificate Enrollment Protocol (SCEP) |
| CVE-2021-3059 | 8.1 HIGH | PAN-OS: OS Command Injection Vulnerability When Performing Dynamic Updates |
| CVE-2021-3061 | 6.4 MEDIUM | PAN-OS: OS Command Injection Vulnerability in the Command Line Interface (CLI) |
No comments yet