Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1310 CNY

100%

Cloud NGFW — Vulnerabilities & Security Advisories 50

All 50 CVE vulnerabilities found in Cloud NGFW, with AI-generated Chinese analysis, references, and POCs.

This page aggregates known vulnerability data for the Cloud NGFW product, focusing on general weakness classifications and associated tags. It compiles security issues ranging from remote code execution and privilege escalation to information disclosure and denial of service conditions. The collection encompasses historical records spanning multiple years, capturing both resolved patches and currently active exposure windows. By centralizing this information, the resource provides a comprehensive view of the product's security posture over time. Readers can utilize this repository to track vendor advisories and monitor how specific threats have been addressed or mitigated by the provider. It also allows for a deeper understanding of prevalent weakness classes, such as those defined by the Common Weakness Enumeration, within the context of cloud-native firewall architecture. Furthermore, users can look up a specific product’s vulnerability history to identify patterns, recurring issues, or systemic flaws that may impact deployment strategies. This structured approach aids security teams in prioritizing remediation efforts based on severity and relevance. The data is organized to facilitate efficient searching and cross-referencing, ensuring that administrators can quickly assess risk levels without wading through unstructured logs. This resource serves as a critical reference for compliance auditing, threat modeling, and ongoing security assessments. By maintaining an up-to-date inventory of past incidents, it supports proactive decision-making and helps organizations stay informed about the evolving threat landscape affecting their Cloud NGFW deployments.

Vendor: Palo Alto Networks

CVE IDTitleCVSSSeverityPublished
CVE-2025-0109 PAN-OS: Unauthenticated File Deletion Vulnerability on the Management Web Interface CWE-73 9.1 -2025-02-12
CVE-2025-0108 PAN-OS: Authentication Bypass in the Management Web Interface CWE-306 9.8 -2025-02-12
CVE-2025-0107 Expedition: OS Command Injection Vulnerability CWE-78 10.0 -2025-01-11
CVE-2025-0106 Expedition: Wildcard Expansion Vulnerability CWE-155 5.8 -2025-01-11
CVE-2025-0105 Expedition: Arbitrary File Deletion Vulnerability CWE-73 10.0 -2025-01-11
CVE-2025-0104 Expedition: Cross-Site Scripting (XSS) Vulnerability CWE-79 6.1 -2025-01-11
CVE-2025-0103 Expedition: SQL Injection Vulnerability CWE-89 8.1 -2025-01-11
CVE-2024-3393 PAN-OS: Firewall Denial of Service (DoS) in DNS Security Using a Specially Crafted Packet CWE-754 7.5 -2024-12-27
CVE-2024-9474 PAN-OS: Privilege Escalation (PE) Vulnerability in the Web Management Interface CWE-78 7.2AIHighAI2024-11-18
CVE-2024-0012 PAN-OS: Authentication Bypass in the Management Web Interface (PAN-SA-2024-0015) CWE-306 9.8AICriticalAI2024-11-18
CVE-2024-2550 PAN-OS: Firewall Denial of Service (DoS) in GlobalProtect Gateway Using a Specially Crafted Packet CWE-476 7.5AIHighAI2024-11-14
CVE-2024-5920 PAN-OS: Stored Cross-Site Scripting (XSS) Vulnerability in PAN-OS Enables Impersonation of a Legitimate Administrator CWE-79 4.8AIMediumAI2024-11-14
CVE-2024-5917 PAN-OS: Server-Side Request Forgery in WildFire CWE-918 5.3AIMediumAI2024-11-14
CVE-2024-2552 PAN-OS: Arbitrary File Delete Vulnerability in the Command Line Interface (CLI) CWE-22 6.5AIMediumAI2024-11-14
CVE-2024-5918 PAN-OS: Improper Certificate Validation Enables Impersonation of a Legitimate GlobalProtect User CWE-295 8.1AIHighAI2024-11-14
CVE-2024-5919 PAN-OS: Authenticated XML External Entities (XXE) Injection Vulnerability CWE-611 7.7AIHighAI2024-11-14
CVE-2024-2551 PAN-OS: Firewall Denial of Service (DoS) Using a Specially Crafted Packet CWE-476 7.5AIHighAI2024-11-14
CVE-2024-9472 PAN-OS: Firewall Denial of Service (DoS) Using Specially Crafted Traffic CWE-476 7.5AIHighAI2024-11-14
CVE-2024-9468 PAN-OS: Firewall Denial of Service (DoS) via a Maliciously Crafted Packet CWE-787 7.5AIHighAI2024-10-09
CVE-2022-0028 PAN-OS: Reflected Amplification Denial-of-Service (DoS) Vulnerability in URL Filtering CWE-406 8.6 High2022-08-10

All 50 known CVE vulnerabilities affecting Cloud NGFW with full Chinese analysis, references, and POCs where available.