Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Palo Alto Networks — Vulnerabilities & Security Advisories 342

Browse all 342 CVE security advisories affecting Palo Alto Networks. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Palo Alto Networks operates as a prominent cybersecurity vendor, primarily providing next-generation firewalls, cloud security solutions, and endpoint protection platforms to enterprise clients. The company’s software ecosystem, particularly its PAN-OS operating system, has historically been associated with a significant volume of Common Vulnerabilities and Exposures, currently totaling 280 recorded instances. These vulnerabilities frequently involve remote code execution, cross-site scripting, and privilege escalation flaws, often stemming from input validation errors or improper access controls within management interfaces. While the firm maintains a robust security posture through regular patching cycles and proactive threat intelligence integration, the high CVE count reflects the complexity of its extensive feature set and the broad attack surface inherent in critical infrastructure components. Major incidents have been limited, with most issues resolved via timely updates, though the sheer number of disclosed flaws underscores the challenges of securing large-scale, continuously updated network security appliances.

Found 122 results / 342 Clear Filters
CVE ID Title CVSS Severity Published
CVE-2020-2014 PAN-OS: OS injection vulnerability in PAN-OS management server — PAN-OS CWE-78 8.8 High 2020-05-13
CVE-2020-2015 PAN-OS: Buffer overflow in the management server — PAN-OS CWE-120 8.8 High 2020-05-13
CVE-2020-2016 PAN-OS: Temporary file race condition vulnerability in PAN-OS leads to local privilege escalation — PAN-OS CWE-377 7.0 High 2020-05-13
CVE-2020-2017 PAN-OS: DOM-Based cross site scripting vulnerability in management web interface — PAN-OS CWE-79 8.8 High 2020-05-13
CVE-2020-2018 PAN-OS: Panorama authentication bypass vulnerability — PAN-OS CWE-287 9.0 Critical 2020-05-13
CVE-2020-1993 PAN-OS: GlobalProtect Portal PHP session fixation vulnerability — PAN-OS CWE-384 3.7 Low 2020-05-13
CVE-2020-1994 PAN-OS: Predictable temporary file vulnerability — PAN-OS CWE-377 4.1 Medium 2020-05-13
CVE-2020-1995 PAN-OS: Management server rasmgr denial of service — PAN-OS CWE-476 4.9 Medium 2020-05-13
CVE-2020-1996 PAN-OS: Panorama management server log injection — PAN-OS CWE-862 5.3 Medium 2020-05-13
CVE-2020-1997 PAN-OS: GlobalProtect registration open redirect — PAN-OS CWE-601 5.3 Medium 2020-05-13
CVE-2020-1998 PAN-OS: Improper SAML SSO authorization of shared local users — PAN-OS CWE-285 5.4 Medium 2020-05-13
CVE-2020-2001 PAN-OS: Panorama External control of file vulnerability leads to privilege escalation — PAN-OS CWE-123 8.1 High 2020-05-13
CVE-2020-2002 PAN-OS: Spoofed Kerberos key distribution center authentication bypass — PAN-OS CWE-290 8.1 High 2020-05-13
CVE-2020-2003 PAN-OS: Authenticated administrator can delete arbitrary system file — PAN-OS CWE-73 6.5 Medium 2020-05-13
CVE-2020-2005 PAN-OS: GlobalProtect Clientless VPN session hijacking — PAN-OS CWE-79 7.1 High 2020-05-13
CVE-2020-2006 PAN-OS: Buffer overflow in management server payload parser — PAN-OS CWE-121 7.2 High 2020-05-13
CVE-2020-2007 PAN-OS: OS command injection in management server — PAN-OS CWE-78 7.2 High 2020-05-13
CVE-2020-2008 PAN-OS: OS command injection or arbitrary file deletion vulnerability — PAN-OS CWE-73 7.2 High 2020-05-13
CVE-2020-2009 PAN-OS: Panorama SD WAN arbitrary file creation — PAN-OS CWE-73 7.2 High 2020-05-13
CVE-2020-2010 PAN-OS: Authenticated user command injection vulnerability — PAN-OS CWE-78 7.2 High 2020-05-13
CVE-2020-1992 PAN-OS on PA-7000 Series: Varrcvr daemon network-based denial of service or privilege escalation — PAN-OS CWE-134 8.1 High 2020-04-08
CVE-2020-1990 PAN-OS: Buffer overflow in the management server — PAN-OS CWE-121 7.2 High 2020-04-08
CVE-2020-1979 PAN-OS: A format string vulnerability in PAN-OS log daemon (logd) on Panorama allows local privilege escalation — PAN-OS CWE-134 8.1 High 2020-03-11
CVE-2020-1980 PAN-OS: Shell injection vulnerability in PAN-OS CLI allows execution of shell commands — PAN-OS CWE-77 7.8 High 2020-03-11
CVE-2020-1981 PAN-OS: Predictable temporary filename vulnerability allows local privilege escalation — PAN-OS CWE-377 7.0 High 2020-03-11
CVE-2020-1975 Missing XML Validation in PAN-OS Web Interface — PAN-OS CWE-112 6.8 Medium 2020-02-12
CVE-2019-17440 PAN-OS on PA-7000 Series: Improper restriction of communication to Log Forwarding Card (LFC) allows root access — PAN-OS CWE-923 10.0 Critical 2019-12-20
CVE-2019-17437 PAN-OS: Custom-role users may escalate privileges — PAN-OS CWE-280 7.8 High 2019-12-05
CVE-2019-1581 PAN-OS: Remote code execution vulnerability in the PAN-OS SSH device management interface — PAN-OS CWE-78 9.8 Critical 2019-08-23
CVE-2019-1572 Palo Alto Networks PAN-OS 授权问题漏洞 — PAN-OS 7.5 - 2019-03-26

This page lists every published CVE security advisory associated with Palo Alto Networks. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.