📦 Pan Os

by Paloaltonetworks

🔍 What is Pan Os?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-0108

CRITICAL CVSS 9.1 Feb 12, 2025

An authentication bypass vulnerability in Palo Alto Networks PAN-OS software allows unauthenticated attackers with network access to the management web interface to bypass authentication and invoke ce...

CVE-2024-0012

CRITICAL CVSS 9.8 Nov 18, 2024

An authentication bypass vulnerability in Palo Alto Networks PAN-OS software allows unauthenticated attackers with network access to the management web interface to gain administrator privileges. This...

CVE-2024-3400

CRITICAL CVSS 10.0 Apr 12, 2024

CVE-2024-3400 is a critical command injection vulnerability in Palo Alto Networks PAN-OS GlobalProtect feature that allows unauthenticated attackers to execute arbitrary code with root privileges. It ...

CVE-2021-3064

CRITICAL CVSS 9.8 Nov 10, 2021

This is a critical memory corruption vulnerability in Palo Alto Networks GlobalProtect portal and gateway interfaces that allows unauthenticated attackers with network access to potentially execute ar...

CVE-2020-2040

CRITICAL CVSS 9.8 Sep 9, 2020

A critical buffer overflow vulnerability in PAN-OS allows unauthenticated attackers to send malicious requests to the Captive Portal or Multi-Factor Authentication interface, potentially executing arb...

CVE-2026-0227

HIGH CVSS 7.5 Jan 15, 2026

An unauthenticated attacker can send specially crafted requests to Palo Alto Networks PAN-OS firewalls, causing them to crash and enter maintenance mode. This denial-of-service vulnerability affects a...

CVE-2025-4615

HIGH CVSS 7.2 Oct 9, 2025

An authenticated administrator can bypass system restrictions in Palo Alto Networks PAN-OS management web interface to execute arbitrary commands. This affects PAN-OS firewall administrators with web ...

CVE-2025-4231

HIGH CVSS 7.2 Jun 13, 2025

An authenticated command injection vulnerability in Palo Alto Networks PAN-OS allows administrative users with management interface access to execute arbitrary commands with root privileges. This affe...

CVE-2025-0114

HIGH CVSS 7.5 Mar 12, 2025

An unauthenticated attacker can cause a Denial of Service (DoS) in Palo Alto Networks PAN-OS GlobalProtect by sending specially crafted packets over time, rendering the GlobalProtect portal and gatewa...

CVE-2024-3393

HIGH CVSS 7.5 Dec 27, 2024

An unauthenticated attacker can send a malicious DNS packet through a Palo Alto Networks firewall's data plane, causing the firewall to reboot. Repeated exploitation forces the firewall into maintenan...

CVE-2024-9474

HIGH CVSS 7.2 Nov 18, 2024

This CVE describes a privilege escalation vulnerability in Palo Alto Networks PAN-OS software where an authenticated administrator with access to the management web interface can execute commands with...

CVE-2024-2550

HIGH CVSS 7.5 Nov 14, 2024

An unauthenticated attacker can send a specially crafted packet to Palo Alto Networks PAN-OS GlobalProtect gateways, causing a null pointer dereference that stops the GlobalProtect service. Repeated e...

CVE-2024-8686

HIGH CVSS 7.2 Sep 11, 2024

This CVE describes a command injection vulnerability in Palo Alto Networks PAN-OS software that allows authenticated administrators to bypass system restrictions and execute arbitrary commands with ro...

CVE-2024-8691

HIGH CVSS 7.1 Sep 11, 2024

This vulnerability allows an authenticated GlobalProtect user to impersonate another GlobalProtect user, disconnecting the legitimate user while hiding the attacker's identity in logs. It affects Palo...

CVE-2024-3384

HIGH CVSS 7.5 Apr 10, 2024

A vulnerability in Palo Alto Networks PAN-OS software allows remote attackers to reboot firewalls by sending Windows NTLM packets from Windows servers. Repeated exploitation can force firewalls into m...

CVE-2024-3382

HIGH CVSS 7.5 Apr 10, 2024

A memory leak vulnerability in Palo Alto Networks PAN-OS software allows attackers to send crafted packets that eventually cause the firewall to stop processing traffic. This affects only PA-5400 Seri...

CVE-2023-6790

HIGH CVSS 8.8 Dec 13, 2023

This DOM-based XSS vulnerability in Palo Alto Networks PAN-OS allows attackers to execute malicious JavaScript in an administrator's browser by tricking them into clicking a specially crafted link. Th...

CVE-2022-0024

HIGH CVSS 7.2 May 11, 2022

This vulnerability in Palo Alto Networks PAN-OS software allows authenticated administrators to upload malicious configurations that can disrupt system processes and potentially execute arbitrary code...

CVE-2021-3059

HIGH CVSS 8.1 Nov 10, 2021

This CVE-2021-3059 is an OS command injection vulnerability in Palo Alto Networks PAN-OS management interface that allows man-in-the-middle attackers to execute arbitrary OS commands and escalate priv...

CVE-2021-3062

HIGH CVSS 8.1 Nov 10, 2021

An improper access control vulnerability in PAN-OS allows authenticated GlobalProtect users to access the EC2 instance metadata endpoint on AWS-hosted VM-Series firewalls. This enables attackers to pe...

CVE-2021-3056

HIGH CVSS 8.8 Nov 10, 2021

A memory corruption vulnerability in Palo Alto Networks PAN-OS GlobalProtect Clientless VPN allows authenticated attackers to execute arbitrary code with root privileges during SAML authentication. Th...

CVE-2021-3053

HIGH CVSS 7.5 Sep 8, 2021

An unauthenticated attacker can send specially crafted network traffic through Palo Alto Networks PAN-OS firewalls to crash the dataplane service. Repeated exploitation causes the device to restart in...

CVE-2025-0111

MEDIUM CVSS 6.5 Feb 12, 2025

An authenticated file read vulnerability in Palo Alto Networks PAN-OS software allows authenticated attackers with management web interface access to read files accessible by the 'nobody' user. This a...

CVE-2024-5920

MEDIUM CVSS 4.8 Nov 14, 2024

This XSS vulnerability in Palo Alto Networks PAN-OS allows an authenticated read-write Panorama administrator to push malicious configurations to PAN-OS nodes, enabling impersonation of legitimate adm...

CVE-2024-5918

MEDIUM CVSS 4.3 Nov 14, 2024

An improper certificate validation vulnerability in Palo Alto Networks PAN-OS allows an authorized user with a specially crafted client certificate to connect to GlobalProtect portal/gateway as a diff...

CVE-2024-2552

MEDIUM CVSS 6.0 Nov 14, 2024

This CVE describes a command injection vulnerability in Palo Alto Networks PAN-OS software that allows authenticated administrators to bypass system restrictions and delete files on the firewall. The ...

CVE-2024-8688

MEDIUM CVSS 4.4 Sep 11, 2024

This vulnerability allows authenticated administrators (including read-only admins) with CLI access to read arbitrary files on Palo Alto Networks firewalls. It affects PAN-OS systems where administrat...

CVE-2024-5916

MEDIUM CVSS 4.4 Aug 14, 2024

This vulnerability in Palo Alto Networks PAN-OS allows read-only administrators with config log access to unintentionally view secrets, passwords, and tokens for external systems. It affects organizat...

CVE-2024-5913

MEDIUM CVSS 6.1 Jul 10, 2024

An improper input validation vulnerability in Palo Alto Networks PAN-OS software allows attackers with physical file system access to elevate privileges. This affects PAN-OS firewalls and Panorama man...

CVE-2025-4614

LOW CVSS 2.7 Oct 9, 2025

An authenticated administrator in Palo Alto Networks PAN-OS software can view session tokens of users logged into the firewall web UI, potentially enabling impersonation of those users. This affects P...