Vulnerabilidades em Palo Alto Networks

330 resultados
Análise Vexday

Das 316 CVEs catalogadas para Palo Alto Networks, 13 estão confirmadas em exploração ativa no catálogo KEV da CISA, representando uma taxa 9,1 vezes acima da média geral do catálogo — sinal de que vulnerabilidades nesse vendor atraem exploração real com frequência desproporcional. A CVE mais crítica em atividade é a CVE-2024-3400, que atingiu EPSS máximo de 1,0, indicando probabilidade extremamente elevada de exploração observada ou iminente. O tipo de falha mais recorrente é CWE-78 (injeção de comandos no sistema operacional), uma classe de vulnerabilidade com alto potencial de impacto em appliances de segurança de perímetro. Com 17 CVEs críticas, 15 com PoC pública e 39 surgidas nos últimos 90 dias, equipes responsáveis por ambientes que utilizam produtos Palo Alto Networks devem priorizar ciclos curtos de patching e monitorar ativamente os indicadores de exploração.

CVE-2024-9466HIGHExpedition: Cleartext Storage of Information Leads to Firewall Admin Credential DisclosureEPSS 12.9%CVE-2020-2034HIGHPAN-OS: OS command injection vulnerability in GlobalProtect portalEPSS 7.2%CVE-2020-2021CRITICALPAN-OS: Authentication Bypass in SAML AuthenticationEPSS 4.4%KEVCVE-2020-2040CRITICALPAN-OS: Buffer overflow when Captive Portal or Multi-Factor Authentication (MFA) is enabledEPSS 3.9%CVE-2018-10141GlobalProtect Portal Login page in Palo Alto Networks PAN-OS before 8.1.4 allows an unauthenticated attacker to inject arbitrary JavaScript EPSS 3.9%CVE-2020-2037HIGHPAN-OS: OS command injection vulnerability in the management web interfaceEPSS 3.6%CVE-2020-1992HIGHPAN-OS on PA-7000 Series: Varrcvr daemon network-based denial of service or privilege escalationEPSS 3.4%CVE-2020-2000HIGHPAN-OS: OS command injection and memory corruption vulnerabilityEPSS 3.4%CVE-2019-1581CRITICALPAN-OS: Remote code execution vulnerability in the PAN-OS SSH device management interfaceEPSS 3.2%CVE-2020-2008HIGHPAN-OS: OS command injection or arbitrary file deletion vulnerabilityEPSS 2.8%CVE-2020-2014HIGHPAN-OS: OS injection vulnerability in PAN-OS management serverEPSS 2.7%CVE-2020-2030HIGHPAN-OS: OS command injection vulnerability in the management interfaceEPSS 2.5%CVE-2019-1572PAN-OS 9.0.0 may allow an unauthenticated remote user to access php files.EPSS 2.5%CVE-2022-0028HIGHPAN-OS: Reflected Amplification Denial-of-Service (DoS) Vulnerability in URL FilteringEPSS 2.4%KEVCVE-2020-2042HIGHPAN-OS: Buffer overflow in the management web interfaceEPSS 2.3%CVE-2020-2007HIGHPAN-OS: OS command injection in management serverEPSS 2.2%CVE-2020-2010HIGHPAN-OS: Authenticated user command injection vulnerabilityEPSS 2.2%CVE-2018-10142The Expedition Migration tool 1.0.106 and earlier may allow an unauthenticated attacker to enumerate files on the operating system.EPSS 2.2%CVE-2020-2041HIGHPAN-OS: Management web interface denial-of-service (DoS)EPSS 2.1%CVE-2020-1990HIGHPAN-OS: Buffer overflow in the management serverEPSS 2.1%