Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

PAN-OS — Vulnerabilities & Security Advisories 122

All 122 CVE vulnerabilities found in PAN-OS, with AI-generated Chinese analysis, references, and POCs.

This page aggregates Common Weakness Enumerations associated with PAN-OS, the operating system for Palo Alto Networks firewall appliances. It serves as a comprehensive resource for security professionals seeking to understand the specific attack surfaces and historical flaws within this network security platform. The collection includes a wide range of vulnerability types, from remote code execution and privilege escalation flaws to information disclosure and denial of service issues affecting various PAN-OS versions. The data spans multiple years, capturing both critical high-severity findings and lower-risk configuration weaknesses that have been publicly disclosed or patched over time. By consulting this aggregation, you can effectively track a vendor's advisory history and identify patterns in how Palo Alto Networks addresses security defects in their firmware. This resource allows you to understand a weakness class in the context of enterprise-grade network infrastructure, helping you assess the relevance of specific flaws to your own deployment environment. Furthermore, you can look up a product's vulnerability history to determine if older or specific PAN-OS versions remain exposed to known exploits. This structured view aids in prioritizing patching efforts and strengthening network defenses against targeted attacks. The information provided is strictly technical, focusing on the existence and classification of flaws without promotional commentary or external links, ensuring a neutral and factual reference point for security auditing and risk assessment activities within organizations utilizing PAN-OS based security appliances.

Vendor: Palo Alto Networks

CVE IDTitleCVSSSeverityPublished
CVE-2023-6792 PAN-OS: OS Command Injection Vulnerability in the XML API CWE-88 5.5 Medium2023-12-13
CVE-2023-6790 PAN-OS: DOM-Based Cross-Site Scripting (XSS) Vulnerability in the Web Interface CWE-79 8.8 High2023-12-13
CVE-2023-38046 PAN-OS: Read System Files and Resources During Configuration Commit CWE-610 5.5 Medium2023-07-12
CVE-2023-0010 PAN-OS: Reflected Cross-Site Scripting (XSS) Vulnerability in Captive Portal Authentication CWE-79 5.4 Medium2023-06-14
CVE-2023-0008 PAN-OS: Local File Disclosure Vulnerability in the PAN-OS Web Interface CWE-73 4.4 Medium2023-05-10
CVE-2023-0007 PAN-OS: Stored Cross-Site Scripting (XSS) Vulnerability in the Panorama Web Interface CWE-80 6.5 Medium2023-05-10
CVE-2023-0005 PAN-OS: Exposure of Sensitive Information Vulnerability CWE-497 4.1 Medium2023-04-12
CVE-2023-0004 PAN-OS: Local File Deletion Vulnerability CWE-703 6.5 Medium2023-04-12
CVE-2022-0030 PAN-OS: Authentication Bypass in Web Interface CWE-290 8.1 High2022-10-12
CVE-2022-0024 PAN-OS: Improper Neutralization Vulnerability Leads to Unintended Program Execution During Configuration Commit CWE-138 7.2 High2022-05-11
CVE-2022-0023 PAN-OS: Denial-of-Service (DoS) Vulnerability in DNS Proxy CWE-755 5.9 Medium2022-04-13
CVE-2022-0022 PAN-OS: Use of a Weak Cryptographic Algorithm for Stored Password Hashes CWE-916 4.1 Medium2022-03-09
CVE-2022-0011 PAN-OS: URL Category Exceptions Match More URLs Than Intended in URL Filtering CWE-436 6.5 Medium2022-02-10
CVE-2021-3064 PAN-OS: Memory Corruption Vulnerability in GlobalProtect Portal and Gateway Interfaces CWE-121 9.8 Critical2021-11-10
CVE-2021-3063 PAN-OS: Denial-of-Service (DoS) Vulnerability in GlobalProtect Portal and Gateway Interfaces CWE-755 7.5 High2021-11-10
CVE-2021-3062 PAN-OS: Improper Access Control Vulnerability Exposing AWS Instance Metadata Endpoint to GlobalProtect Users CWE-284 8.1 High2021-11-10
CVE-2021-3061 PAN-OS: OS Command Injection Vulnerability in the Command Line Interface (CLI) CWE-78 6.4 Medium2021-11-10
CVE-2021-3060 PAN-OS: OS Command Injection in Simple Certificate Enrollment Protocol (SCEP) CWE-78 8.1 High2021-11-10
CVE-2021-3059 PAN-OS: OS Command Injection Vulnerability When Performing Dynamic Updates CWE-78 8.1 High2021-11-10
CVE-2021-3058 PAN-OS: OS Command Injection Vulnerability in Web Interface XML API CWE-78 8.8 High2021-11-10
CVE-2021-3056 PAN-OS: Memory Corruption Vulnerability in GlobalProtect Clientless VPN During SAML Authentication CWE-120 8.8 High2021-11-10
CVE-2021-3055 PAN-OS: XML External Entity (XXE) Reference Vulnerability in the PAN-OS Web Interface CWE-611 6.5 Medium2021-09-08
CVE-2021-3054 PAN-OS: Unsigned Code Execution During Plugin Installation Race Condition Vulnerability CWE-367 7.2 High2021-09-08
CVE-2021-3053 PAN-OS: Exceptional Condition Denial-of-Service (DoS) CWE-755 7.5 High2021-09-08
CVE-2021-3052 PAN-OS: Reflected Cross-Site Scripting (XSS) in Web Interface CWE-79 8.0 High2021-09-08
CVE-2021-3050 PAN-OS: OS Command Injection Vulnerability in Web Interface CWE-78 8.8 High2021-08-11
CVE-2021-3048 PAN-OS: Invalid URLs in an External Dynamic List (EDL) can Lead to Firewall Outage CWE-20 5.9 Medium2021-08-11
CVE-2021-3047 PAN-OS: Weak Cryptography Used in Web Interface Authentication CWE-338 4.2 Medium2021-08-11
CVE-2021-3046 PAN-OS: Improper SAML Authentication Vulnerability in GlobalProtect Portal CWE-287 6.8 Medium2021-08-11
CVE-2021-3045 PAN-OS: OS Command Argument Injection in Web Interface CWE-88 4.9 Medium2021-08-11

All 122 known CVE vulnerabilities affecting PAN-OS with full Chinese analysis, references, and POCs where available.