Palo Alto Networks PAN-OS是美国Palo Alto Networks公司的一套为其防火墙设备开发的操作系统。 Palo Alto Networks PAN-OS存在安全漏洞,该漏洞源于信息暴露,使得GlobalProtect端用户能够获知配置的GlobalProtect卸载密码和配置的禁用或断开连接的密码,从而导致即使按GlobalProtect应用程序配置通常不允许的情况下,终端用户也可以进行卸载、禁用或断开操作。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Palo Alto Networks | PAN-OS | 11.0.0 ~ 11.0.1 | - |
|
| Palo Alto Networks | GlobalProtect App | 5.1.0 ~ 5.1.12 | - |
|
| Palo Alto Networks | Cloud NGFW | - | - |
|
| Palo Alto Networks | Prisma Access | 10.2.0 ~ 10.2.9 on PAN-OS | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2024-8691 | PAN-OS: User Impersonation in GlobalProtect Portal | |
| CVE-2024-8690 | Cortex XDR Agent: Local Windows Administrator Can Disable the Agent | |
| CVE-2024-8689 | ActiveMQ Content Pack: Cleartext Exposure of Credentials | |
| CVE-2024-8688 | PAN-OS: Arbitrary File Read Vulnerability in the Command Line Interface (CLI) | |
| CVE-2024-8686 | PAN-OS: Command Injection Vulnerability |
No comments yet