Skip to main content

Vendor archive

paloaltonetworks CVEs

Beta · best-effort

369 CVEs tagged to vendor paloaltonetworks40 Critical, 127 High, 178 Medium, 24 Low, 0 Unrated.

CVE-2013-5664

Published Aug 31, 2013

Cross-site scripting (XSS) vulnerability in the web-based device-management API browser in Palo Alto Networks PAN-OS before 4.1.13 and 5.0.x before 5.0.6 allows remote attackers t…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-5663

Published Aug 31, 2013

The App-ID cache feature in Palo Alto Networks PAN-OS before 4.0.14, 4.1.x before 4.1.11, and 5.0.x before 5.0.2 allows remote attackers to bypass intended security policies via c…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-6605

Published Aug 31, 2013

The device-management command-line interface in Palo Alto Networks PAN-OS before 3.1.11 and 4.0.x before 4.0.9 allows remote authenticated users to execute arbitrary code via unsp…

CVSS 9.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2012-6604

Published Aug 31, 2013

The device-management command-line interface in Palo Alto Networks PAN-OS before 3.1.11 and 4.0.x before 4.0.9 allows remote authenticated users to execute arbitrary code via unsp…

CVSS 9.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2012-6603

Published Aug 31, 2013

The web management UI in Palo Alto Networks PAN-OS before 3.1.12, 4.0.x before 4.0.10, and 4.1.x before 4.1.4 allows remote attackers to bypass authentication and obtain administr…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2012-6602

Published Aug 31, 2013

The device-management command-line interface in Palo Alto Networks PAN-OS before 3.1.10 and 4.0.x before 4.0.4 allows remote authenticated users to execute arbitrary commands via…

CVSS 9.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2012-6601

Published Aug 31, 2013

The device-management command-line interface in Palo Alto Networks PAN-OS before 3.1.12, 4.0.x before 4.0.10, and 4.1.x before 4.1.4 allows remote attackers to execute arbitrary c…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2012-6600

Published Aug 31, 2013

The device-management command-line interface in Palo Alto Networks PAN-OS 4.0.x before 4.0.9 and 4.1.x before 4.1.2 allows remote authenticated users to execute arbitrary commands…

CVSS 9.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2012-6599

Published Aug 31, 2013

The device-management command-line interface in Palo Alto Networks PAN-OS 4.0.x before 4.0.8 and 4.1.x before 4.1.1 allows remote authenticated users to execute arbitrary commands…

CVSS 9.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2012-6598

Published Aug 31, 2013

The device-management command-line interface in Palo Alto Networks PAN-OS 4.0.x before 4.0.8 allows remote authenticated users to execute arbitrary commands via unspecified vector…

CVSS 9.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2012-6597

Published Aug 31, 2013

Palo Alto Networks PAN-OS before 3.1.11 and 4.0.x before 4.0.9 allows remote authenticated users to cause a denial of service (management-server crash) by using the command-line i…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-6596

Published Aug 31, 2013

Palo Alto Networks PAN-OS 4.0.x before 4.0.9 and 4.1.x before 4.1.3 stores cleartext LDAP bind passwords in authd.log, which allows context-dependent attackers to obtain sensitive…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-6595

Published Aug 31, 2013

The device-management command-line interface in Palo Alto Networks PAN-OS 4.0.x before 4.0.9 and 4.1.x before 4.1.2 allows remote authenticated administrators to execute arbitrary…

CVSS 9.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2012-6594

Published Aug 31, 2013

The device-management command-line interface in Palo Alto Networks PAN-OS before 3.1.11, 4.0.x before 4.0.8, and 4.1.x before 4.1.1 allows remote authenticated administrators to e…

CVSS 9.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2012-6593

Published Aug 31, 2013

Palo Alto Networks PAN-OS before 3.1.10 and 4.0.x before 4.0.4 allows remote attackers to execute arbitrary commands via unspecified vectors, aka Ref ID 30088.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2012-6592

Published Aug 31, 2013

Palo Alto Networks PAN-OS before 3.1.10 and 4.0.x before 4.0.5 allows remote attackers to execute arbitrary commands via unspecified vectors, aka Ref ID 31091.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2012-6591

Published Aug 31, 2013

The device-management command-line interface in Palo Alto Networks PAN-OS before 3.1.10 and 4.0.x before 4.0.5 allows remote authenticated administrators to execute arbitrary comm…

CVSS 9.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2012-6590

Published Aug 31, 2013

The web-based management UI in Palo Alto Networks PAN-OS 4.0.x before 4.0.8 allows remote attackers to obtain verbose error information via crafted input, aka Ref ID 33139.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 351-369 of 369 CVEsPage 15 of 15