Palo Alto Networks Security Advisories

1 - 25 of 41
VersionsAffectedUnaffected
iPAN-SA-2024-0014 Informational Bulletin: Impact of OSS CVEs in Cortex XDR Agent
Cortex XDR Agent
None
All
2024-11-07
5.7CVE-2024-9469 Cortex XDR Agent: Local Windows User Can Disable the Agent
Cortex XDR Agent 8.6
Cortex XDR Agent 8.5
Cortex XDR Agent 8.4
Cortex XDR Agent 8.3-CE
Cortex XDR Agent 8.3
Cortex XDR Agent 7.9-CE
None
None
< 8.4.1 on Windows
None
< 8.3.1 on Windows
< 7.9.102-CE on Windows
All
All
>= 8.4.1 on Windows
All
>= 8.3.1 on Windows
>= 7.9.102-CE on Windows
2024-10-092024-10-09
iCVE-2024-47076 Informational: No Impact of CUPS Vulnerabilities on Palo Alto Networks Products
Cloud NGFW
Cortex XDR
Cortex XDR Agent
Cortex XSIAM
Cortex XSOAR
GlobalProtect App
PAN-OS
Prisma Access
Prisma Access Browser
Prisma Cloud
Prisma Cloud Compute
Prisma SD-WAN
None
None
None
None
None
None
None
None
None
None
None
None
All
All
All
All
All
All
All
All
All
All
All
All
2024-09-262024-09-26
5.6CVE-2024-8690 Cortex XDR Agent: Local Windows Administrator Can Disable the Agent
Cortex XDR Agent 8.5
Cortex XDR Agent 8.4
Cortex XDR Agent 8.3-CE
Cortex XDR Agent 8.3
Cortex XDR Agent 8.2
Cortex XDR Agent 7.9.102-CE
None
None
None
None
None
All
All
All
All
All
All
None
2024-09-112024-09-11
iCVE-2024-5535 Informational Bulletin: Impact of OpenSSL Vulnerabilities CVE-2024-5535 and CVE-2024-6119
None
all
2024-08-222024-09-04
6.8CVE-2024-5912 Cortex XDR Agent: Improper File Signature Verification Checks
Cortex XDR Agent 8.5
Cortex XDR Agent 8.4
Cortex XDR Agent 8.3-CE
Cortex XDR Agent 8.3
Cortex XDR Agent 8.2
Cortex XDR Agent 7.9-CE
None
None
None
None
< 8.2.2
< 7.9.102-CE
All
All
All
All
>= 8.2.2
>= 7.9.102-CE
2024-07-102024-07-10
6.8CVE-2024-5909 Cortex XDR Agent: Local Windows User Can Disable the Agent
Cortex XDR Agent 8.4
Cortex XDR Agent 8.3
Cortex XDR Agent 8.2
Cortex XDR Agent 8.1
Cortex XDR Agent 7.9-CE
None
None
< 8.2.1 on Windows
< 8.1.2 on Windows
< 7.9.102-CE on Windows
All
All
>= 8.2.1 on Windows
>= 8.1.2 on Windows
>= 7.9.102-CE on Windows
2024-06-122024-06-12
5.2CVE-2024-5907 Cortex XDR Agent: Local Privilege Escalation (PE) Vulnerability
Cortex XDR Agent 8.4
Cortex XDR Agent 8.3
Cortex XDR Agent 8.2
Cortex XDR Agent 8.1
Cortex XDR Agent 7.9-CE
None
< 8.3.1 on Windows
< 8.2.3 on Windows
All
< 7.9.102-CE on Windows
All
>= 8.3.1 on Windows
>= 8.2.3 on Windows
None
>= 7.9.102-CE on Windows
2024-06-122024-06-12
2CVE-2024-5905 Cortex XDR Agent: Local Windows User Can Disrupt Functionality of the Agent
Cortex XDR Agent 8.4
Cortex XDR Agent 8.3
Cortex XDR Agent 8.2
Cortex XDR Agent 8.1
Cortex XDR Agent 7.9-CE
None
None
< 8.2.1 on Windows
< 8.1.2 on Windows
< 7.9.102-CE on Windows
All
All
>= 8.2.1 on Windows
>= 8.1.2 on Windows
>= 7.9.102-CE on Windows
2024-06-122024-06-12
iPAN-SA-2024-0005 Informational Bulletin: Proof of Concept (PoC) Bypasses Protection Modules in Cortex XDR Agent
Cortex XDR Agent 8.4
Cortex XDR Agent 8.3
Cortex XDR Agent 8.2
Cortex XDR Agent 8.1
Cortex XDR Agent 8.0
Cortex XDR Agent 7.9
Cortex XDR Agent 5.0
< Agents with content update earlier than CU-1320 on Windows
< Agents with content update earlier than CU-1320 on Windows
< Agents with content update earlier than CU-1320 on Windows
< Agents with content update earlier than CU-1320 on Windows
< Agents with content update earlier than CU-1320 on Windows
< Agents with content update earlier than CU-1320 on Windows
All agents on Windows
>= Agents with CU-1320 or a later content update on Windows
>= Agents with CU-1320 or a later content update on Windows
>= Agents with CU-1320 or a later content update on Windows
>= Agents with CU-1320 or a later content update on Windows
>= Agents with CU-1320 or a later content update on Windows
>= Agents with CU-1320 or a later content update on Windows
None
2024-04-242024-04-24
iCVE-2024-3094 Informational: Impact of Malicious Code in XZ Tools and Libraries (CVE-2024-3094)
None
all
2024-04-012024-04-01
iCVE-2023-38545 Impact of curl and libcurl Vulnerabilities (CVE-2023-38545, CVE-2023-38546)
None
all
2023-10-122023-10-31
iCVE-2023-44487 Impact of Rapid Reset and HTTP/2 DoS Vulnerabilities (CVE-2023-44487, CVE-2023-35945)
None
all
2023-10-112023-10-25
5.5CVE-2023-3280 Cortex XDR Agent: Local Windows User Can Disable the Agent
Cortex XDR Agent 8.1
Cortex XDR Agent 8.0
Cortex XDR Agent 7.9-CE
Cortex XDR Agent 7.9
Cortex XDR Agent 7.5-CE
Cortex XDR Agent 5.0
None
< 8.0.2 on Windows
< 7.9.101-CE on Windows
< 7.9.3 on Windows
All on Windows
All on Windows
All
>= 8.0.2 with CU-1000 or a later content update on Windows
>= 7.9.101-CE with CU-1000 or a later content update on Windows
>= 7.9.3 with CU-1000 or a later content update on Windows
None
None
2023-09-132023-09-22
iPAN-SA-2023-0003 Informational Bulletin: Impact of MOVEit Vulnerabilities (CVE-2023-34362, CVE-2023-35036, CVE-2023-35708)
None
all
2023-06-162023-06-20
iPAN-SA-2023-0002 Informational Bulletin: Impact of Rorschach Ransomware
Cortex XDR Agent 5.0
Cortex XDR Agent 7.5 CE
Cortex XDR Agent 7.8
Cortex XDR Agent 7.9 CE
Cortex XDR Agent 8.0
All agents on Windows
All agents on Windows
< Agents with content update earlier than CU-240 on Windows
< Agents with content update earlier than CU-240 on Windows
< Agents with content update earlier than CU-240 on Windows
None
None
>= Agents with CU-240 or a later content update on Windows
>= Agents with CU-240 or a later content update on Windows
>= Agents with CU-240 or a later content update on Windows
2023-04-042023-04-12
6CVE-2023-0001 Cortex XDR Agent: Cleartext Exposure of Agent Admin Password
Cortex XDR Agent 7.9
Cortex XDR Agent 7.8
Cortex XDR Agent 7.5
Cortex XDR Agent 5.0
None
None
< 7.5.101-CE on Windows
None
All
All
>= 7.5.101-CE on Windows
All
2023-02-082023-02-08
5.5CVE-2023-0002 Cortex XDR Agent: Product Disruption by Local Windows User
Cortex XDR Agent 7.9
Cortex XDR Agent 7.8
Cortex XDR Agent 7.5
Cortex XDR Agent 5.0
None
None
< 7.5.101-CE on Windows
< 5.0.12.22203 on Windows
All
All
>= 7.5.101-CE on Windows
>= 5.0.12.22203 on Windows
2023-02-082023-02-08
iPAN-SA-2023-0001 Impact of OpenSSL Vulnerabilities Disclosed Feb 7, 2023
None
all
2023-02-082023-02-08
iPAN-SA-2022-0007 Impact of OpenSSL 3.0 Vulnerability CVE-2022-3996
None
all
2022-12-232022-12-23
iCVE-2022-42889 Impact of Apache Text Commons Vulnerability CVE-2022-42889
None
all
2022-11-092022-11-09
iPAN-SA-2022-0006 Impact of OpenSSL 3.0 Vulnerabilities CVE-2022-3786 and CVE-2022-3602
None
all
2022-10-312022-11-09
5.5CVE-2022-0029 Cortex XDR Agent: Improper Link Resolution Vulnerability When Generating a Tech Support File
Cortex XDR Agent 7.5 CE
Cortex XDR Agent 7.8
Cortex XDR Agent 7.7
Cortex XDR Agent 5.0
< 7.5.101-CE on Windows
None
< 7.7.3 on Windows
< 5.0.12-hotfix update on Windows
>= 7.5.101-CE
All
>= 7.7.3
>= 5.0.12-hotfix update
2022-09-142022-09-14
iPAN-SA-2022-0004 Informational: Cortex XDR Agent: Allow List is Visible to Low Privileged Users
Cortex XDR Agent
All agents with a content update earlier than CU-630 on Windows
All agents with CU-630 or a later content update
2022-09-142022-09-14
iPAN-SA-2022-0005 Informational: Cortex XDR Agent: Product Disruption by Local Windows Administrator
Cortex XDR Agent
All agents with a content update earlier than CU-860 on Windows
All agents with CU-860 or a later content update
2022-09-142023-03-08
1 - 25 of 41 Download
© 2024 Palo Alto Networks, Inc. All rights reserved.