Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Palo Alto Networks — Vulnerabilities & Security Advisories 342

Browse all 342 CVE security advisories affecting Palo Alto Networks. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Palo Alto Networks operates as a prominent cybersecurity vendor, primarily providing next-generation firewalls, cloud security solutions, and endpoint protection platforms to enterprise clients. The company’s software ecosystem, particularly its PAN-OS operating system, has historically been associated with a significant volume of Common Vulnerabilities and Exposures, currently totaling 280 recorded instances. These vulnerabilities frequently involve remote code execution, cross-site scripting, and privilege escalation flaws, often stemming from input validation errors or improper access controls within management interfaces. While the firm maintains a robust security posture through regular patching cycles and proactive threat intelligence integration, the high CVE count reflects the complexity of its extensive feature set and the broad attack surface inherent in critical infrastructure components. Major incidents have been limited, with most issues resolved via timely updates, though the sheer number of disclosed flaws underscores the challenges of securing large-scale, continuously updated network security appliances.

CVE ID Title CVSS Severity Published
CVE-2020-2040 PAN-OS: Buffer overflow when Captive Portal or Multi-Factor Authentication (MFA) is enabled — PAN-OS CWE-120 9.8 Critical 2020-09-09
CVE-2020-2041 PAN-OS: Management web interface denial-of-service (DoS) — PAN-OS CWE-16 7.5 High 2020-09-09
CVE-2020-2038 PAN-OS: OS command injection vulnerability in the management web interface — PAN-OS CWE-78 7.2 High 2020-09-09
CVE-2020-2039 PAN-OS: Management web interface denial-of-service (DoS) through unauthenticated file upload — PAN-OS CWE-400 5.3 Medium 2020-09-09
CVE-2020-2036 PAN-OS: Reflected Cross-Site Scripting (XSS) vulnerability in management web interface — PAN-OS CWE-79 8.8 High 2020-09-09
CVE-2020-2037 PAN-OS: OS command injection vulnerability in the management web interface — PAN-OS CWE-78 7.2 High 2020-09-09
CVE-2020-2035 PAN-OS: URL filtering policy is not enforced on TLS handshakes for decrypted HTTPS sessions — PAN-OS CWE-20 3.0 Low 2020-08-12
CVE-2020-2034 PAN-OS: OS command injection vulnerability in GlobalProtect portal — PAN-OS CWE-78 8.1 High 2020-07-08
CVE-2020-2030 PAN-OS: OS command injection vulnerability in the management interface — PAN-OS CWE-78 7.2 High 2020-07-08
CVE-2020-2031 PAN-OS: Integer underflow in the management interface — PAN-OS CWE-191 4.9 Medium 2020-07-08
CVE-2020-1982 PAN-OS: TLS 1.0 usage for certain communications with Palo Alto Networks cloud delivered services — PAN-OS CWE-326 4.8 Medium 2020-07-08
CVE-2020-2021 PAN-OS: Authentication Bypass in SAML Authentication — PAN-OS CWE-347 10.0 Critical 2020-06-29
CVE-2020-2033 GlobalProtect App: Missing certificate validation vulnerability can disclose pre-logon authentication cookie — GlobalProtect App CWE-290 5.3 Medium 2020-06-10
CVE-2020-2032 GlobalProtect App: File race condition vulnerability leads to local privilege escalation during upgrade — GlobalProtect App CWE-367 7.0 High 2020-06-10
CVE-2020-2029 PAN-OS: OS command injection vulnerability in management interface certificate generator — PAN-OS CWE-78 7.2 High 2020-06-10
CVE-2020-2028 PAN-OS: OS command injection vulnerability in FIPS-CC mode certificate verification — PAN-OS CWE-78 7.2 High 2020-06-10
CVE-2020-2027 PAN-OS: Buffer overflow in authd authentication response — PAN-OS CWE-121 7.2 High 2020-06-10
CVE-2020-2011 PAN-OS: Panorama registration denial of service — PAN-OS CWE-20 7.5 High 2020-05-13
CVE-2020-2012 PAN-OS: Panorama: XML external entity reference ('XXE') vulnerability leads the to information leak — PAN-OS CWE-611 7.5 High 2020-05-13
CVE-2020-2013 PAN-OS: Panorama context switch session cookie disclosure — PAN-OS CWE-319 8.3 High 2020-05-13
CVE-2020-2014 PAN-OS: OS injection vulnerability in PAN-OS management server — PAN-OS CWE-78 8.8 High 2020-05-13
CVE-2020-2015 PAN-OS: Buffer overflow in the management server — PAN-OS CWE-120 8.8 High 2020-05-13
CVE-2020-2016 PAN-OS: Temporary file race condition vulnerability in PAN-OS leads to local privilege escalation — PAN-OS CWE-377 7.0 High 2020-05-13
CVE-2020-2017 PAN-OS: DOM-Based cross site scripting vulnerability in management web interface — PAN-OS CWE-79 8.8 High 2020-05-13
CVE-2020-2018 PAN-OS: Panorama authentication bypass vulnerability — PAN-OS CWE-287 9.0 Critical 2020-05-13
CVE-2020-1993 PAN-OS: GlobalProtect Portal PHP session fixation vulnerability — PAN-OS CWE-384 3.7 Low 2020-05-13
CVE-2020-1994 PAN-OS: Predictable temporary file vulnerability — PAN-OS CWE-377 4.1 Medium 2020-05-13
CVE-2020-1995 PAN-OS: Management server rasmgr denial of service — PAN-OS CWE-476 4.9 Medium 2020-05-13
CVE-2020-1996 PAN-OS: Panorama management server log injection — PAN-OS CWE-862 5.3 Medium 2020-05-13
CVE-2020-1997 PAN-OS: GlobalProtect registration open redirect — PAN-OS CWE-601 5.3 Medium 2020-05-13

This page lists every published CVE security advisory associated with Palo Alto Networks. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.