Palo Alto Networks Security Advisories

1 - 25 of 254
VersionsAffectedUnaffected
7.8CVE-2021-3041 Cortex XDR Agent: Improper control of user-controlled file leads to local privilege escalation
Cortex XDR Agent 7.2
Cortex XDR Agent 6.1
Cortex XDR Agent 5.0
< 7.2.3 or without content update 171 or later
< 6.1.8
< 5.0.11
>= 7.2.3 with content update 171 or later
>= 6.1.8
>= 5.0.11
2021-06-092021-06-09
6.7CVE-2021-3040 Bridgecrew Checkov: Unsafe deserialization of Terraform files allows code execution
Bridgecrew Checkov 2.0
Bridgecrew Checkov 1.0
< 2.0.139
none
>= 2.0.139
all
2021-06-092021-06-09
3.8CVE-2021-3039 Prisma Cloud Compute: User role authorization secret for Console leaked through log file export
Prisma Cloud Compute 20.04
< 21.04.412
>= 21.04.412
2021-06-092021-06-09
0PAN-SA-2021-0003 Informational: Impact of the NAME:WRECK DNS vulnerabilities
PAN-OS
CloudGenix
none
none
all
all
2021-05-102021-05-12
6.7CVE-2021-3035 Bridgecrew Checkov: Unsafe deserialization of Terraform files allows code execution
Bridgecrew Checkov 2.0
Bridgecrew Checkov 1.0
< 2.0.26
none
>= 2.0.26
all
2021-04-142021-04-14
5.5CVE-2021-3038 GlobalProtect App: Windows VPN kernel driver denial of service (DoS)
GlobalProtect App 5.2
GlobalProtect App 5.1
< 5.2.4 on Windows
< 5.1.8 on Windows
>= 5.2.4 on Windows
>= 5.1.8 on Windows
2021-04-142021-04-20
4.4CVE-2021-3036 PAN-OS: Administrator secrets are logged in web server logs when using the PAN-OS XML API incorrectly
PAN-OS 10.0
PAN-OS 9.1
PAN-OS 9.0
PAN-OS 8.1
< 10.0.1
< 9.1.6
< 9.0.12
< 8.1.19
>= 10.0.1
>= 9.1.6
>= 9.0.12
>= 8.1.19
2021-04-142021-04-14
2.3CVE-2021-3037 PAN-OS: Secrets for scheduled configuration exports are logged in system logs
PAN-OS 10.0
PAN-OS 9.1
PAN-OS 9.0
PAN-OS 8.1
none
< 9.1.4
< 9.0.13
< 8.1.19
>= 10.0.0
>= 9.1.4
>= 9.0.13
>= 8.1.19
2021-04-142021-04-14
0CVE-2021-28041 PAN-OS: Informational: Impact of the OpenSSH vulnerability CVE-2021-28041
PAN-OS
none
all
2021-03-242021-04-14
5.1CVE-2021-3034 Cortex XSOAR: Secrets for SAML single sign-on (SSO) integration may be logged in system logs
Cortex XSOAR 6.1.0
Cortex XSOAR 6.0.2
Cortex XSOAR 6.0.1
Cortex XSOAR 5.5.0
< 848144
< 98623
< 830029
< 98622
>= 848144
>= 98623
none
>= 98622
2021-03-102021-03-15
9.1 NCVE-2021-3033 Prisma Cloud Compute: SAML Authentication Bypass Vulnerability in Console
Prisma Cloud Compute 20.12
Prisma Cloud Compute 20.09
Prisma Cloud Compute 20.04
Prisma Cloud Compute 19.11
<= 20.12.535
<= 20.09.365
<= 20.04.177
<= 19.11.*
>= 20.12.541
>= 20.09.374
>= 20.04.183
none
2021-02-102021-02-26
0CVE-2021-3156 Informational: Impact of Sudo Vulnerability CVE-2021-3156
Prisma Cloud compute
PAN-OS
CloudGenix
none
none
none
all
all
all
2021-02-102021-02-10
0PAN-SA-2021-0002 Informational: PAN-OS: NAT slipstreaming v1.0 and v2.0 attacks
PAN-OS
none
all
2021-02-102021-03-10
0CVE-2020-27619 Informational: Impact of Python Test Suite Vulnerability CVE-2020-27619
PAN-OS
Cortex XSOAR
none
none
all
all
2021-02-102021-02-10
4.4CVE-2021-3032 PAN-OS: Configuration secrets for log forwarding may be logged in system logs
PAN-OS 10.0
PAN-OS 9.1
PAN-OS 9.0
PAN-OS 8.1
< 10.0.1
< 9.1.4
< 9.0.12
< 8.1.18
>= 10.0.1
>= 9.1.4
>= 9.0.12
>= 8.1.18
2021-01-132021-01-13
4.3CVE-2021-3031 PAN-OS: Information exposure in Ethernet data frame construction (Etherleak)
PAN-OS 10.0
PAN-OS 9.1
PAN-OS 9.0
PAN-OS 8.1
PAN-OS 8.0
PAN-OS 7.1
none
< 9.1.5 on PA-220, PA-800, PA-3000 Series, PA-3200 Series, PA-5200 Series, PA-7000 Series
< 9.0.12 on PA-220, PA-800, PA-3000 Series, PA-3200 Series, PA-5200 Series, PA-7000 Series
< 8.1.18 on PA-200, PA-220, PA-500, PA-5000 Series, PA-800, PA-3000 Series, PA-3200 Series, PA-5200 Series, PA-7000 Series
8.0.* on PA-200, PA-220, PA-500, PA-5000 Series, PA-800, PA-3000 Series, PA-3200 Series, PA-5200 Series, PA-7000 Series
7.1.* on PA-200, PA-220, PA-500, PA-5000 Series, PA-800, PA-2000 Series, PA-3000 Series, PA-3200 Series, PA-5200 Series, PA-7000 Series
10.0.*
>= 9.1.5
>= 9.0.12
>= 8.1.18
none
none
2021-01-132021-01-19
0PAN-SA-2021-0001 Informational: Cortex XSOAR: Impact of Golang XML parsing vulnerabilities
Cortex XSOAR 6.0
Cortex XSOAR 5.5
< 6.0.2
none
>= 6.0.2
5.5.*
2021-01-132021-01-13
7.8CVE-2020-2049 Cortex XDR Agent: Improper control of loaded DLL leads to local privilege escalation
Cortex XDR Agent 7.2
Cortex XDR Agent 7.1
Cortex XDR Agent 7.0
Cortex XDR Agent 6.1
7.2.* without content update 150 on Windows
7.1.* without content update 150 on Windows
none
none
7.2.* with content update 150 on Windows
7.1.* with content update 150 on Windows
7.0.* with latest content on Windows
6.1.* with latest content on Windows
2020-12-092020-12-09
5.5CVE-2020-2020 Cortex XDR Agent: Exceptional condition denial-of-service (DoS)
Cortex XDR Agent 7.2
Cortex XDR Agent 7.1
Cortex XDR Agent 7.0
Cortex XDR Agent 6.1
Cortex XDR Agent 5.0
none
< 7.1.2
< 7.0.3
< 6.1.7
< 5.0.10
>= 7.2.0
>= 7.1.2
>= 7.0.3
>= 6.1.7
>= 5.0.10
2020-12-092020-12-09
0PAN-SA-2020-0011 Informational: Impact of OpenSSL vulnerability CVE-2020-1971
PAN-OS
GlobalProtect App
Cortex XSOAR
none
none
none
all
all
all
2020-12-092020-12-09
8.2 NCVE-2020-2050 PAN-OS: Authentication bypass vulnerability in GlobalProtect client certificate verification
PAN-OS 10.0
PAN-OS 9.1
PAN-OS 9.0
PAN-OS 8.1
< 10.0.1
< 9.1.5
< 9.0.11
< 8.1.17
>= 10.0.1
>= 9.1.5
>= 9.0.11
>= 8.1.17
2020-11-112020-11-19
7.5CVE-2020-2022 PAN-OS: Panorama session disclosure during context switch into managed device
PAN-OS 10.0
PAN-OS 9.1
PAN-OS 9.0
PAN-OS 8.1
none
< 9.1.5
< 9.0.11
< 8.1.17
10.0.*
>= 9.1.5
>= 9.0.11
>= 8.1.17
2020-11-112020-11-11
7.2CVE-2020-2000 PAN-OS: OS command injection and memory corruption vulnerability
PAN-OS 10.0
PAN-OS 9.1
PAN-OS 9.0
PAN-OS 8.1
< 10.0.1
< 9.1.4
< 9.0.10
< 8.1.16
>= 10.0.1
>= 9.1.4
>= 9.0.10
>= 8.1.16
2020-11-112021-02-24
5.3 NCVE-2020-1999 PAN-OS: Threat signatures are evaded by specifically crafted packets
PAN-OS 10.0
PAN-OS 9.1
PAN-OS 9.0
PAN-OS 8.1
PAN-OS 8.0
PAN-OS 7.1
none
< 9.1.5
< 9.0.11
< 8.1.17
8.0.*
7.1.*
10.0.*
>= 9.1.5
>= 9.0.11
>= 8.1.17
none
none
2020-11-112020-11-13
3.3CVE-2020-2048 PAN-OS: System proxy passwords may be logged in clear text while viewing system state
PAN-OS 10.0
PAN-OS 9.1
PAN-OS 9.0
PAN-OS 8.1
none
< 9.1.2
< 9.0.11
< 8.1.17
10.0.*
>= 9.1.2
>= 9.0.11
>= 8.1.17
2020-11-112020-11-11
1 - 25 of 254 Download
N = Exploitable over the network with low complexity, unauthenticated attack.
© 2020 Palo Alto Networks, Inc. All rights reserved.