Vulnerabilidades en Palo Alto Networks

330 resultados
Análisis Vexday

Das 316 CVEs catalogadas para Palo Alto Networks, 13 estão confirmadas em exploração ativa no catálogo KEV da CISA, representando uma taxa 9,1 vezes acima da média geral do catálogo — sinal de que vulnerabilidades nesse vendor atraem exploração real com frequência desproporcional. A CVE mais crítica em atividade é a CVE-2024-3400, que atingiu EPSS máximo de 1,0, indicando probabilidade extremamente elevada de exploração observada ou iminente. O tipo de falha mais recorrente é CWE-78 (injeção de comandos no sistema operacional), uma classe de vulnerabilidade com alto potencial de impacto em appliances de segurança de perímetro. Com 17 CVEs críticas, 15 com PoC pública e 39 surgidas nos últimos 90 dias, equipes responsáveis por ambientes que utilizam produtos Palo Alto Networks devem priorizar ciclos curtos de patching e monitorar ativamente os indicadores de exploração.

CVE-2024-3400CRITICALPAN-OS: Arbitrary File Creation Leads to OS Command Injection Vulnerability in GlobalProtectEPSS 100.0%KEVCVE-2024-0012CRITICALPAN-OS: Authentication Bypass in the Management Web Interface (PAN-SA-2024-0015)EPSS 99.7%KEVCVE-2024-9465CRITICALExpedition: SQL Injection Leads to Firewall Admin Credential DisclosureEPSS 99.6%KEVCVE-2024-9463CRITICALExpedition: Unauthenticated OS Command Injection Vulnerability Leads to Firewall Credential DisclosureEPSS 98.5%KEVCVE-2025-0108HIGHPAN-OS: Authentication Bypass in the Management Web InterfaceEPSS 98.5%KEVCVE-2024-9474MEDIUMPAN-OS: Privilege Escalation (PE) Vulnerability in the Web Management InterfaceEPSS 94.8%KEVCVE-2026-0257HIGHPAN-OS: GlobalProtect Authentication Bypass VulnerabilitiesEPSS 93.9%KEVCVE-2024-5910CRITICALExpedition: Missing Authentication Leads to Admin Account TakeoverEPSS 91.8%KEVCVE-2020-2038HIGHPAN-OS: OS command injection vulnerability in the management web interfaceEPSS 86.1%CVE-2024-9464CRITICALExpedition: Authenticated OS Command Injection Vulnerability Leads to Firewall Admin Credential DisclosureEPSS 81.8%CVE-2025-0107HIGHExpedition: OS Command Injection VulnerabilityEPSS 78.5%CVE-2025-0133LOWPAN-OS: Reflected Cross-Site Scripting (XSS) Vulnerability in GlobalProtect Gateway and PortalEPSS 46.4%CVE-2020-2039MEDIUMPAN-OS: Management web interface denial-of-service (DoS) through unauthenticated file uploadEPSS 46.4%CVE-2021-3060HIGHPAN-OS: OS Command Injection in Simple Certificate Enrollment Protocol (SCEP)EPSS 33.9%CVE-2026-0300CRITICALPAN-OS: Unauthenticated user initiated Buffer Overflow Vulnerability in User-ID™ Authentication PortalEPSS 32.1%KEVCVE-2024-3393HIGHPAN-OS: Firewall Denial of Service (DoS) in DNS Security Using a Specially Crafted PacketEPSS 28.6%KEVCVE-2018-10143The Palo Alto Networks Expedition Migration tool 1.0.107 and earlier may allow an unauthenticated attacker with remote access to run system EPSS 24.8%CVE-2020-2036HIGHPAN-OS: Reflected Cross-Site Scripting (XSS) vulnerability in management web interfaceEPSS 23.9%CVE-2021-3064CRITICALPAN-OS: Memory Corruption Vulnerability in GlobalProtect Portal and Gateway InterfacesEPSS 19.1%CVE-2025-0105MEDIUMExpedition: Arbitrary File Deletion VulnerabilityEPSS 13.0%