| i | PAN-SA-2025-0005
GlobalProtect Clientless VPN: Clientless VPN Misconfiguration Allows Cross-Site Attacks | Cloud NGFW PAN-OS Prisma Access | | | 2025-02-12 | 2025-02-12 |
| 5.3 | CVE-2024-3596
PAN-OS: CHAP and PAP When Used with RADIUS Authentication Lead to Privilege Escalation | Cloud NGFW PAN-OS 11.2 PAN-OS 11.1 PAN-OS 11.0 PAN-OS 10.2 PAN-OS 10.1 PAN-OS 9.1 Prisma Access | None None < 11.1.3 < 11.0.4-h5, < 11.0.6 < 10.2.4-h21, < 10.2.7-h21, < 10.2.8-h20, < 10.2.9-h8, < 10.2.10 < 10.1.12-h4, < 10.1.14 < 9.1.19 None | All All >= 11.1.3 >= 11.0.4-h5, >= 11.0.6 >= 10.2.4-h21, >= 10.2.7-h21, >= 10.2.8-h20, >= 10.2.9-h8, >= 10.2.10 >= 10.1.12-h4, >= 10.1.14 >= 9.1.19 All | 2024-07-10 | 2025-04-30 |
| 6 | CVE-2023-48795
Impact of Terrapin SSH Attack | PAN-OS 12.1 PAN-OS 11.2 PAN-OS 11.1 PAN-OS 11.0 PAN-OS 10.2 PAN-OS 10.1 PAN-OS 9.1 PAN-OS 9.0 | None < 11.2.8 < 11.1.8 All < 10.2.14 All All All | All >= 11.2.8 >= 11.1.8 ¹ None ² >= 10.2.14 ¹ None None None | 2024-01-09 | 2026-03-10 |
| 10 | CVE-2021-44228
Impact of Log4j Vulnerabilities CVE-2021-44228, CVE-2021-45046, CVE-2021-45105, and CVE-2021-44832 | Bridgecrew Cortex Data Lake Cortex XDR Agent Cortex XSOAR Cortex Xpanse Enterprise Data Loss Prevention Exact Data Matching CLI Expedition GlobalProtect App IoT Security Okyo Garde PAN-DB Private Cloud PAN-OS PAN-OS 10.1 PAN-OS 10.0 PAN-OS 9.1 PAN-OS 9.0 PAN-OS 8.1 Prisma Cloud Prisma Access Prisma Cloud Compute Prisma SD-WAN (CloudGenix) SaaS Security Traps User-ID Agent WildFire Appliance (WF-500) WildFire Cloud | None None None None None None < 2.1 None None None None None None on Firewall, WildFire None on Panorama < 10.0.8-h8 on Panorama < 9.1.12-h3 on Panorama < 9.0.15 on Panorama None on Panorama None None None None None None None None None | All All All All All All >= 2.1 All All All All All All on Firewall, WildFire All on Panorama >= 10.0.8-h8 on Panorama >= 9.1.12-h3 on Panorama >= 9.0.15 on Panorama All on Panorama All All All All All All All All All | 2021-12-10 | 2022-01-22 |
| 8.8 | CVE-2021-3056
PAN-OS: Memory Corruption Vulnerability in GlobalProtect Clientless VPN During SAML Authentication | PAN-OS 10.1 PAN-OS 10.0 PAN-OS 9.1 PAN-OS 9.0 PAN-OS 8.1 Prisma Access 2.2 Prisma Access 2.1 | None < 10.0.1 < 9.1.9 < 9.0.14 < 8.1.20 None Preferred | All >= 10.0.1 >= 9.1.9 >= 9.0.14 >= 8.1.20 All Innovation | 2021-11-10 | 2021-11-10 |
| 8.8 | CVE-2021-3050
PAN-OS: OS Command Injection Vulnerability in Web Interface | PAN-OS 10.1 PAN-OS 10.0 PAN-OS 9.1 PAN-OS 9.0 PAN-OS 8.1 | >= 10.1.0 >= 10.0.0 >= 9.1.4 >= 9.0.10 None | >= 10.1.2 >= 10.0.8 >= 9.1.11 >= 9.0.15 8.1.* | 2021-08-11 | 2021-08-11 |
| 3 | CVE-2020-2035
PAN-OS: URL filtering policy is not enforced on TLS handshakes for decrypted HTTPS sessions | PAN-OS 10.1 PAN-OS 10.0 PAN-OS 9.1 PAN-OS 9.0 PAN-OS 8.1 | All without CTD inspection enabled All All All All | None with CTD inspection enabled None None None None | 2020-08-12 | 2021-07-20 |