Palo Alto Networks PAN-OS是美国Palo Alto Networks公司的一款下一代防火墙软件。 Palo Alto Networks PAN-OS 存在安全漏洞,该漏洞源于存在一个不正确的字符串比较漏洞,导致预定义解密排除无法按预期运行。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Palo Alto Networks | Cloud NGFW | All |
unaffected |
| Palo Alto Networks | PAN-OS | 9.0.0< 9.0.17-h2 |
affected |
9.1.0< 9.1.17 |
affected | ||
10.0.0< 10.0.13 |
affected | ||
10.1.0< 10.1.9-h3 |
affected | ||
10.1.0< 10.1.10 |
affected | ||
10.2.0< 10.2.4-h2 |
affected | ||
10.2.0< 10.2.5 |
affected | ||
11.0.0< 11.0.1-h2 |
affected | ||
| … +2 more rows | |||
| Palo Alto Networks | Prisma Access | All |
unaffected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Palo Alto Networks | PAN-OS | 9.0.0 ~ 9.0.17-h2 | - |
|
| Palo Alto Networks | Cloud NGFW | - | - |
|
| Palo Alto Networks | Prisma Access | - | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2024-3382 | 7.5 HIGH | PAN-OS: Firewall Denial of Service (DoS) via a Burst of Crafted Packets |
| CVE-2024-3384 | 7.5 HIGH | PAN-OS: Firewall Denial of Service (DoS) via Malformed NTLM Packets |
| CVE-2024-3385 | 7.5 HIGH | PAN-OS: Firewall Denial of Service (DoS) when GTP Security is Disabled |
| CVE-2024-3383 | 7.4 HIGH | PAN-OS: Improper Group Membership Change Vulnerability in Cloud Identity Engine (CIE) |
| CVE-2024-3387 | 5.3 MEDIUM | PAN-OS: Weak Certificate Strength in Panorama Software Leads to Sensitive Information Disc |
| CVE-2024-3388 | 4.1 MEDIUM | PAN-OS: User Impersonation in GlobalProtect SSL VPN |
No comments yet