VendorsPalo Alto Networkspan-osall versions
Vulnerabilities

Palo Alto Networks paloaltonetworks pan-os

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

235CVEs
CVE-2024-3400
PAN-OS: Arbitrary File Creation Leads to OS Command Injection Vulnerability in GlobalProtect
Published 2024-04-12 · Analyzed
10.0KEV1 PoCEPSS 1.000
CVE-2016-9150
Buffer overflow in the management web interface in Palo Alto Networks PAN-OS before 5.0.20, 5.1.x before 5.1.13, 6.0.x before 6.0.15, 6.1.x before 6.1.15, 7.0.x before 7.0.11, and 7.1.x before 7.1.6 allows remote attackers to execute arbitrary code via unspecified vectors.
Published 2016-11-19 · Modified
10.01 PoCEPSS 0.348
CVE-2021-3064
PAN-OS: Memory Corruption Vulnerability in GlobalProtect Portal and Gateway Interfaces
Published 2021-11-10 · Modified
10.0EPSS 0.201
CVE-2017-8390
The DNS Proxy in Palo Alto Networks PAN-OS before 6.1.18, 7.x before 7.0.16, 7.1.x before 7.1.11, and 8.x before 8.0.3 allows remote attackers to execute arbitrary code via a crafted domain name.
Published 2017-08-02 · Modified
10.0EPSS 0.061
CVE-2016-3657
Buffer overflow in the GlobalProtect Portal in Palo Alto Networks PAN-OS before 5.0.18, 6.0.x before 6.0.13, 6.1.x before 6.1.10, and 7.0.x before 7.0.5 allows remote attackers to cause a denial of service (device crash) or possibly execute arbitrary code via an SSL VPN request.
Published 2016-04-12 · Modified
10.0EPSS 0.048
CVE-2012-6603
The web management UI in Palo Alto Networks PAN-OS before 3.1.12, 4.0.x before 4.0.10, and 4.1.x before 4.1.4 allows remote attackers to bypass authentication and obtain administrator privileges via unspecified vectors, aka Ref ID 37034.
Published 2013-08-31 · Modified
10.0EPSS 0.044
CVE-2012-6601
The device-management command-line interface in Palo Alto Networks PAN-OS before 3.1.12, 4.0.x before 4.0.10, and 4.1.x before 4.1.4 allows remote attackers to execute arbitrary code via unspecified vectors, aka Ref ID 36983.
Published 2013-08-31 · Modified
10.0EPSS 0.044
CVE-2020-2021
PAN-OS: Authentication Bypass in SAML Authentication
Published 2020-06-29 · Analyzed
10.0KEVEPSS 0.044
CVE-2012-6592
Palo Alto Networks PAN-OS before 3.1.10 and 4.0.x before 4.0.5 allows remote attackers to execute arbitrary commands via unspecified vectors, aka Ref ID 31091.
Published 2013-08-31 · Modified
10.0EPSS 0.041
CVE-2012-6593
Palo Alto Networks PAN-OS before 3.1.10 and 4.0.x before 4.0.4 allows remote attackers to execute arbitrary commands via unspecified vectors, aka Ref ID 30088.
Published 2013-08-31 · Modified
10.0EPSS 0.041
CVE-2020-2040
PAN-OS: Buffer overflow when Captive Portal or Multi-Factor Authentication (MFA) is enabled
Published 2020-09-09 · Modified
10.0EPSS 0.039
CVE-2019-1580
Memory corruption in PAN-OS 7.1.24 and earlier, PAN-OS 8.0.19 and earlier, PAN-OS 8.1.9 and earlier, and PAN-OS 9.0.3 and earlier will allow a remote, unauthenticated user to craft a message to Secure Shell Daemon (SSHD) and corrupt arbitrary memory.
Published 2019-08-23 · Modified
10.0EPSS 0.032
CVE-2016-3655
The management web interface in Palo Alto Networks PAN-OS before 5.0.18, 6.0.x before 6.0.13, 6.1.x before 6.1.10, and 7.0.x before 7.0.5 allows remote attackers to execute arbitrary OS commands via an unspecified API call.
Published 2016-04-12 · Modified
10.0EPSS 0.032
CVE-2019-17440
PAN-OS on PA-7000 Series: Improper restriction of communication to Log Forwarding Card (LFC) allows root access
Published 2019-12-20 · Modified
10.0EPSS 0.017
CVE-2026-0284
PAN-OS: XML Injection Vulnerability in Large Scale VPN (LSVPN)
Published 2026-07-09 · Modified
9.9EPSS 0.005
CVE-2024-0012
PAN-OS: Authentication Bypass in the Management Web Interface (PAN-SA-2024-0015)
Published 2024-11-18 · Analyzed
9.8KEVEPSS 0.998
CVE-2017-15944
Palo Alto Networks PAN-OS before 6.1.19, 7.0.x before 7.0.19, 7.1.x before 7.1.14, and 8.0.x before 8.0.6 allows remote attackers to execute arbitrary code via vectors involving the management interface.
Published 2017-12-11 · Analyzed
9.8KEV2 PoCEPSS 0.983
CVE-2026-0300
PAN-OS: Unauthenticated user initiated Buffer Overflow Vulnerability in User-ID™ Authentication Portal
Published 2026-05-06 · Analyzed
9.8KEVEPSS 0.317
CVE-2017-15940
The web interface packet capture management component in Palo Alto Networks PAN-OS before 6.1.19, 7.0.x before 7.0.19, 7.1.x before 7.1.14, and 8.0.x before 8.0.6 allows remote authenticated users to execute arbitrary code via unspecified vectors.
Published 2017-12-11 · Modified
9.8EPSS 0.049
CVE-2020-1992
PAN-OS on PA-7000 Series: Varrcvr daemon network-based denial of service or privilege escalation
Published 2020-04-08 · Modified
9.8EPSS 0.035
CVE-2019-1581
PAN-OS: Remote code execution vulnerability in the PAN-OS SSH device management interface
Published 2019-08-23 · Modified
9.8EPSS 0.032
CVE-2017-9458
XML external entity (XXE) vulnerability in the GlobalProtect internal and external gateway interface in Palo Alto Networks PAN-OS before 6.1.18, 7.0.x before 7.0.17, 7.1.x before 7.1.12, and 8.0.x before 8.0.3 allows remote attackers to obtain sensitive information, cause a denial of service, or conduct server-side request forgery (SSRF) attacks via unspecified vectors.
Published 2017-09-07 · Modified
9.8EPSS 0.025
CVE-2017-7945
The GlobalProtect external interface in Palo Alto Networks PAN-OS before 6.1.17, 7.x before 7.0.15, 7.1.x before 7.1.9, and 8.x before 8.0.2 provides different error messages for failed login attempts depending on whether the username exists, which allows remote attackers to enumerate account names and conduct brute-force attacks via a series of requests, aka PAN-SA-2017-0014 and PAN-72769.
Published 2017-04-29 · Modified
9.8EPSS 0.018
CVE-2020-2001
PAN-OS: Panorama External control of file vulnerability leads to privilege escalation
Published 2020-05-13 · Modified
9.8EPSS 0.013
CVE-2026-0264
PAN-OS: Heap-Based Buffer Overflow in DNS Proxy and DNS Server Allows Unauthenticated Remote Code Execution
Published 2026-05-13 · Analyzed
9.8EPSS 0.005
CVE-2026-0263
PAN-OS: Remote Code Execution (RCE) in IKEv2 Processing
Published 2026-05-13 · Analyzed
9.8EPSS 0.004
CVE-2021-3060
PAN-OS: OS Command Injection in Simple Certificate Enrollment Protocol (SCEP)
Published 2021-11-10 · Modified
9.3EPSS 0.339
CVE-2020-2034
PAN-OS: OS command injection vulnerability in GlobalProtect portal
Published 2020-07-08 · Modified
9.3EPSS 0.072
CVE-2015-6531
Palo Alto Networks Panorama VM Appliance with PAN-OS before 6.0.1 might allow remote attackers to execute arbitrary Python code via a crafted firmware image file.
Published 2017-06-01 · Modified
9.3EPSS 0.029
CVE-2020-2018
PAN-OS: Panorama authentication bypass vulnerability
Published 2020-05-13 · Modified
9.3EPSS 0.013
CVE-2025-0108
PAN-OS: Authentication Bypass in the Management Web Interface
Published 2025-02-12 · Analyzed
9.1KEVEPSS 0.985
CVE-2026-0257
PAN-OS: GlobalProtect Authentication Bypass Vulnerabilities
Published 2026-05-13 · Analyzed
9.1KEVEPSS 0.964
CVE-2024-3383
PAN-OS: Improper Group Membership Change Vulnerability in Cloud Identity Engine (CIE)
Published 2024-04-10 · Analyzed
9.1EPSS 0.006
CVE-2026-0258
PAN-OS: Server-Side Request Forgery (SSRF) in IKEv2 Certificate URL Fetching
Published 2026-05-13 · Analyzed
9.1EPSS 0.003
CVE-2020-2038
PAN-OS: OS command injection vulnerability in the management web interface
Published 2020-09-09 · Modified
9.01 PoCEPSS 0.861
CVE-2020-2037
PAN-OS: OS command injection vulnerability in the management web interface
Published 2020-09-09 · Modified
9.0EPSS 0.036
CVE-2020-2000
PAN-OS: OS command injection and memory corruption vulnerability
Published 2020-11-12 · Modified
9.0EPSS 0.034
CVE-2012-6604
The device-management command-line interface in Palo Alto Networks PAN-OS before 3.1.11 and 4.0.x before 4.0.9 allows remote authenticated users to execute arbitrary code via unspecified vectors, aka Ref ID 35249.
Published 2013-08-31 · Modified
9.0EPSS 0.032
CVE-2012-6605
The device-management command-line interface in Palo Alto Networks PAN-OS before 3.1.11 and 4.0.x before 4.0.9 allows remote authenticated users to execute arbitrary code via unspecified vectors, aka Ref ID 34896.
Published 2013-08-31 · Modified
9.0EPSS 0.032
CVE-2012-6600
The device-management command-line interface in Palo Alto Networks PAN-OS 4.0.x before 4.0.9 and 4.1.x before 4.1.2 allows remote authenticated users to execute arbitrary commands via unspecified vectors, aka Ref ID 34502.
Published 2013-08-31 · Modified
9.0EPSS 0.031
1 / 6Next →