Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Palo Alto Networks — Vulnerabilities & Security Advisories 342

Browse all 342 CVE security advisories affecting Palo Alto Networks. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Palo Alto Networks operates as a prominent cybersecurity vendor, primarily providing next-generation firewalls, cloud security solutions, and endpoint protection platforms to enterprise clients. The company’s software ecosystem, particularly its PAN-OS operating system, has historically been associated with a significant volume of Common Vulnerabilities and Exposures, currently totaling 280 recorded instances. These vulnerabilities frequently involve remote code execution, cross-site scripting, and privilege escalation flaws, often stemming from input validation errors or improper access controls within management interfaces. While the firm maintains a robust security posture through regular patching cycles and proactive threat intelligence integration, the high CVE count reflects the complexity of its extensive feature set and the broad attack surface inherent in critical infrastructure components. Major incidents have been limited, with most issues resolved via timely updates, though the sheer number of disclosed flaws underscores the challenges of securing large-scale, continuously updated network security appliances.

Found 65 results / 342 Clear Filters
CVE ID Title CVSS Severity Published
CVE-2025-2182 PAN-OS: Firewall Clusters using the MACsec Protocol Expose the Connectivity Association Key (CAK) — Cloud NGFW CWE-312 6.5AI Medium AI 2025-08-13
CVE-2025-4229 PAN-OS: Traffic Information Disclosure Vulnerability — Cloud NGFW CWE-497 5.3AI Medium AI 2025-06-13
CVE-2025-4230 PAN-OS: Authenticated Admin Command Injection Vulnerability Through CLI — Cloud NGFW CWE-78 7.2AI High AI 2025-06-12
CVE-2025-4231 PAN-OS: Authenticated Admin Command Injection Vulnerability in the Management Web Interface — Cloud NGFW CWE-77 7.2AI High AI 2025-06-12
CVE-2025-0136 PAN-OS: Unencrypted Data Transfer when using AES-128-CCM on Intel-based hardware devices — Cloud NGFW CWE-319 7.5AI High AI 2025-05-14
CVE-2025-0137 PAN-OS: Improper Neutralization of Input in the Management Web Interface — Cloud NGFW CWE-83 7.2AI High AI 2025-05-14
CVE-2025-0133 PAN-OS: Reflected Cross-Site Scripting (XSS) Vulnerability in GlobalProtect Gateway and Portal — Cloud NGFW CWE-79 6.1AI Medium AI 2025-05-14
CVE-2025-0130 PAN-OS: Firewall Denial-of-Service (DoS) in the Web-Proxy Feature via a Burst of Maliciously Crafted Packets — Cloud NGFW CWE-754 7.5AI High AI 2025-05-14
CVE-2025-0123 PAN-OS: Information Disclosure Vulnerability in HTTP/2 Packet Captures — Cloud NGFW CWE-312 4.9AI Medium AI 2025-04-11
CVE-2025-0128 PAN-OS: Firewall Denial of Service (DoS) Using a Specially Crafted Packet — Cloud NGFW CWE-754 7.5AI High AI 2025-04-11
CVE-2025-0127 PAN-OS: Authenticated Admin Command Injection Vulnerability in PAN-OS VM-Series — Cloud NGFW CWE-78 7.2AI High AI 2025-04-11
CVE-2025-0126 PAN-OS: Session Fixation Vulnerability in GlobalProtect SAML Login — Cloud NGFW CWE-384 8.8AI High AI 2025-04-11
CVE-2025-0125 PAN-OS: Improper Neutralization of Input in the Management Web Interface — Cloud NGFW CWE-83 7.2AI High AI 2025-04-11
CVE-2025-0124 PAN-OS: Authenticated File Deletion Vulnerability on the Management Web Interface — Cloud NGFW CWE-73 7.1AI High AI 2025-04-11
CVE-2025-0111 PAN-OS: Authenticated File Read Vulnerability in the Management Web Interface — Cloud NGFW CWE-73 6.5 - 2025-02-12
CVE-2025-0109 PAN-OS: Unauthenticated File Deletion Vulnerability on the Management Web Interface — Cloud NGFW CWE-73 9.1 - 2025-02-12
CVE-2025-0108 PAN-OS: Authentication Bypass in the Management Web Interface — Cloud NGFW CWE-306 9.8 - 2025-02-12
CVE-2025-0107 Expedition: OS Command Injection Vulnerability — Cloud NGFW CWE-78 10.0 - 2025-01-11
CVE-2025-0106 Expedition: Wildcard Expansion Vulnerability — Cloud NGFW CWE-155 5.8 - 2025-01-11
CVE-2025-0105 Expedition: Arbitrary File Deletion Vulnerability — Cloud NGFW CWE-73 10.0 - 2025-01-11
CVE-2025-0104 Expedition: Cross-Site Scripting (XSS) Vulnerability — Cloud NGFW CWE-79 6.1 - 2025-01-11
CVE-2025-0103 Expedition: SQL Injection Vulnerability — Cloud NGFW CWE-89 8.1 - 2025-01-11
CVE-2024-3393 PAN-OS: Firewall Denial of Service (DoS) in DNS Security Using a Specially Crafted Packet — Cloud NGFW CWE-754 7.5 - 2024-12-27
CVE-2024-9474 PAN-OS: Privilege Escalation (PE) Vulnerability in the Web Management Interface — Cloud NGFW CWE-78 5.9 Medium 2024-11-18
CVE-2024-0012 PAN-OS: Authentication Bypass in the Management Web Interface (PAN-SA-2024-0015) — Cloud NGFW CWE-306 5.9 Medium 2024-11-18
CVE-2024-2550 PAN-OS: Firewall Denial of Service (DoS) in GlobalProtect Gateway Using a Specially Crafted Packet — Cloud NGFW CWE-476 7.5AI High AI 2024-11-14
CVE-2024-5920 PAN-OS: Stored Cross-Site Scripting (XSS) Vulnerability in PAN-OS Enables Impersonation of a Legitimate Administrator — Cloud NGFW CWE-79 4.8AI Medium AI 2024-11-14
CVE-2024-5917 PAN-OS: Server-Side Request Forgery in WildFire — Cloud NGFW CWE-918 5.3AI Medium AI 2024-11-14
CVE-2024-2552 PAN-OS: Arbitrary File Delete Vulnerability in the Command Line Interface (CLI) — Cloud NGFW CWE-22 6.5AI Medium AI 2024-11-14
CVE-2024-5918 PAN-OS: Improper Certificate Validation Enables Impersonation of a Legitimate GlobalProtect User — Cloud NGFW CWE-295 8.1AI High AI 2024-11-14

This page lists every published CVE security advisory associated with Palo Alto Networks. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.