| | Versions | Affected | Unaffected | | |
---|
1.9 | CVE-2025-0123
PAN-OS: Information Disclosure Vulnerability in HTTP/2 Packet Captures | Cloud NGFW PAN-OS 11.2 PAN-OS 11.1 PAN-OS 10.2 PAN-OS 10.1 Prisma Access | None < 11.2.6 < 11.1.8 < 10.2.15 < 10.1.14-h13 None | All >= 11.2.6 >= 11.1.8 >= 10.2.15 (ETA: 05/15) >= 10.1.14-h13 All | 2025-04-09 | 2025-04-09 |
2 | CVE-2025-0124
PAN-OS: Authenticated File Deletion Vulnerability on the Management Web Interface | Cloud NGFW PAN-OS 11.2 PAN-OS 11.1 PAN-OS 11.0 PAN-OS 10.2 PAN-OS 10.1 Prisma Access | All < 11.2.1 < 11.1.5 < 11.0.6 < 10.2.10 < 10.1.14-h11 None | None (ETA end of April) >= 11.2.1 >= 11.1.5 >= 11.0.6 >= 10.2.10 >= 10.1.14-h11 All | 2025-04-09 | 2025-04-09 |
4.4 | CVE-2025-0125
PAN-OS: Improper Neutralization of Input in the Management Web Interface | Cloud NGFW PAN-OS 11.2 PAN-OS 11.1 PAN-OS 11.0 PAN-OS 10.2 PAN-OS 10.1 Prisma Access | None < 11.2.5 < 11.1.5 < 11.0.6 < 10.2.11 < 10.1.14-h11 None | All >= 11.2.5 >= 11.1.5 >= 11.0.6 >= 10.2.11 >= 10.1.14-h11 All | 2025-04-09 | 2025-04-16 |
6.6 | CVE-2025-0128
PAN-OS: Firewall Denial of Service (DoS) Using a Specially Crafted Packet | Cloud NGFW PAN-OS 11.2 PAN-OS 11.1 PAN-OS 11.0 PAN-OS 10.2 PAN-OS 10.1 Prisma Access | None on PAN-OS < 11.2.3 < 11.1.5 < 11.0.6 < 10.2.10-h17 < 10.1.14-h11 < 10.2.4-h36 on PAN-OS, < 10.2.10-h16 on PAN-OS, < 11.2.4-h5 on PAN-OS | All on PAN-OS >= 11.2.3 >= 11.1.5 >= 11.0.6 >= 10.2.10-h17 >= 10.1.14-h11 >= 10.2.4-h36 on PAN-OS, >= 10.2.10-h16 on PAN-OS, >= 11.2.4-h5 on PAN-OS | 2025-04-09 | 2025-04-09 |
5.6 | CVE-2025-0126
PAN-OS: Session Fixation Vulnerability in GlobalProtect SAML Login | Cloud NGFW PAN-OS 11.2 PAN-OS 11.1 PAN-OS 11.0 PAN-OS 10.2 PAN-OS 10.1 Prisma Access | None < 11.2.3 < 11.1.5 < 11.0.6 < 10.2.4-h25, < 10.2.9-h13, < 10.2.10-h6, < 10.2.11 < 10.1.14-h11 < 10.2.4-h36 on PAN-OS, < 10.2.10-h16 on PAN-OS, < 11.2.4-h5 on PAN-OS | All >= 11.2.3 >= 11.1.5 >= 11.0.6 >= 10.2.4-h25, >= 10.2.9-h13, >= 10.2.10-h6, >= 10.2.11 >= 10.1.14-h11 >= 10.2.4-h36 on PAN-OS, >= 10.2.10-h16 on PAN-OS, >= 11.2.4-h5 on PAN-OS | 2025-04-09 | 2025-04-09 |
4 | CVE-2025-0127
PAN-OS: Authenticated Admin Command Injection Vulnerability in PAN-OS VM-Series | Cloud NGFW PAN-OS 11.2 PAN-OS 11.1 PAN-OS 11.0 PAN-OS 10.2 PAN-OS 10.1 Prisma Access | None None on VM-Series None on VM-Series < 11.0.4 on VM-Series < 10.2.9 on VM-Series < 10.1.14-h13 on VM-Series None | All All on VM-Series All on VM-Series >= 11.0.4 on VM-Series >= 10.2.9 on VM-Series >= 10.1.14-h13 on VM-Series All | 2025-04-09 | 2025-04-09 |
4.3 | CVE-2025-0115
PAN-OS: Authenticated Admin File Read Vulnerability in PAN-OS CLI | Cloud NGFW PAN-OS 11.2 PAN-OS 11.1 PAN-OS 11.0 PAN-OS 10.2 PAN-OS 10.1 Prisma Access | None < 11.2.3 < 11.1.4-h17, < 11.1.5 < 11.0.6 < 10.2.11 < 10.1.14-h11 None | All >= 11.2.3 >= 11.1.4-h17, >= 11.1.5 >= 11.0.6 >= 10.2.11 >= 10.1.14-h11 All | 2025-03-12 | 2025-04-02 |
4.6 | CVE-2025-0114
PAN-OS: Denial of Service (DoS) in GlobalProtect | Cloud NGFW PAN-OS 11.2 PAN-OS 11.1 PAN-OS 11.0 PAN-OS 10.2 PAN-OS 10.1 Prisma Access | None None None < 11.0.2 < 10.2.5 < 10.1.14-h11 None | All All All >= 11.0.2 >= 10.2.5 >= 10.1.14-h11 All | 2025-03-12 | 2025-03-12 |
4.3 | CVE-2025-0116
PAN-OS: Firewall Denial of Service (DoS) Using a Specially Crafted LLDP Frame | Cloud NGFW PAN-OS 11.2 PAN-OS 11.1 PAN-OS 10.2 PAN-OS 10.1 Prisma Access | None < 11.2.5 < 11.1.4-h17, < 11.1.6-h6, < 11.1.8 < 10.2.10-h17, < 10.2.13-h5, < 10.2.14 < 10.1.14-h11 None | All >= 11.2.5 >= 11.1.4-h17, >= 11.1.6-h6, >= 11.1.8 >= 10.2.10-h17, >= 10.2.13-h5, >= 10.2.14 >= 10.1.14-h11 All | 2025-03-12 | 2025-04-04 |
8.8 | CVE-2025-0108
PAN-OS: Authentication Bypass in the Management Web Interface | Cloud NGFW PAN-OS 11.2 PAN-OS 11.1 PAN-OS 10.2 PAN-OS 10.1 Prisma Access | None < 11.2.4-h4, < 11.2.5 < 11.1.2-h18, < 11.1.4-h13, < 11.1.6-h1 < 10.2.7-h24, < 10.2.8-h21, < 10.2.9-h21, < 10.2.10-h14, < 10.2.11-h12, < 10.2.12-h6, < 10.2.13-h3 < 10.1.14-h9 None | All >= 11.2.4-h4, >= 11.2.5 >= 11.1.2-h18, >= 11.1.4-h13, >= 11.1.6-h1 >= 10.2.7-h24, >= 10.2.8-h21, >= 10.2.9-h21, >= 10.2.10-h14, >= 10.2.11-h12, >= 10.2.12-h6, >= 10.2.13-h3 >= 10.1.14-h9 All | 2025-02-12 | 2025-03-06 |
5.5 | CVE-2025-0109
PAN-OS: Unauthenticated File Deletion Vulnerability on the Management Web Interface | Cloud NGFW PAN-OS 11.2 PAN-OS 11.1 PAN-OS 10.2 PAN-OS 10.1 Prisma Access | None < 11.2.4-h4, < 11.2.5 < 11.1.2-h18, < 11.1.4-h13, < 11.1.6-h1 < 10.2.7-h24, < 10.2.8-h21, < 10.2.9-h21, < 10.2.10-h14, < 10.2.11-h12, < 10.2.12-h6, < 10.2.13-h3 < 10.1.14-h9 None | All >= 11.2.4-h4, >= 11.2.5 >= 11.1.2-h18, >= 11.1.4-h13, >= 11.1.6-h1 >= 10.2.7-h24, >= 10.2.8-h21, >= 10.2.9-h21, >= 10.2.10-h14, >= 10.2.11-h12, >= 10.2.12-h6, >= 10.2.13-h3 >= 10.1.14-h9 All | 2025-02-12 | 2025-03-06 |
7.1 | CVE-2025-0111
PAN-OS: Authenticated File Read Vulnerability in the Management Web Interface | Cloud NGFW PAN-OS 11.2 PAN-OS 11.1 PAN-OS 10.2 PAN-OS 10.1 Prisma Access | None < 11.2.4-h4, < 11.2.5 < 11.1.2-h18, < 11.1.4-h13, < 11.1.6-h1 < 10.2.7-h24, < 10.2.8-h21, < 10.2.9-h21, < 10.2.10-h14, < 10.2.11-h12, < 10.2.12-h6, < 10.2.13-h3 < 10.1.14-h9 None | All >= 11.2.4-h4, >= 11.2.5 >= 11.1.2-h18, >= 11.1.4-h13, >= 11.1.6-h1 >= 10.2.7-h24, >= 10.2.8-h21, >= 10.2.9-h21, >= 10.2.10-h14, >= 10.2.11-h12, >= 10.2.12-h6, >= 10.2.13-h3 >= 10.1.14-h9 All | 2025-02-12 | 2025-03-06 |
6.9 | CVE-2024-9474
PAN-OS: Privilege Escalation (PE) Vulnerability in the Web Management Interface | Cloud NGFW PAN-OS 11.2 PAN-OS 11.1 PAN-OS 11.0 PAN-OS 10.2 PAN-OS 10.1 Prisma Access | None < 11.2.0-h1, < 11.2.1-h1, < 11.2.2-h2, < 11.2.3-h3, < 11.2.4-h1 < 11.1.0-h4, < 11.1.1-h2, < 11.1.2-h15, < 11.1.3-h11, < 11.1.4-h7, < 11.1.5-h1 < 11.0.0-h4, < 11.0.1-h5, < 11.0.2-h5, < 11.0.3-h13, < 11.0.4-h6, < 11.0.5-h2, < 11.0.6-h1 < 10.2.0-h4, < 10.2.1-h3, < 10.2.2-h6, < 10.2.3-h14, < 10.2.4-h32, < 10.2.5-h9, < 10.2.6-h6, < 10.2.7-h18, < 10.2.8-h15, < 10.2.9-h16, < 10.2.10-h9, < 10.2.11-h6, < 10.2.12-h2 < 10.1.3-h4, < 10.1.6-h9, < 10.1.8-h8, < 10.1.9-h14, < 10.1.10-h9, < 10.1.11-h10, < 10.1.12-h3, < 10.1.13-h5, < 10.1.14-h6 None | All >= 11.2.0-h1, >= 11.2.1-h1, >= 11.2.2-h2, >= 11.2.3-h3, >= 11.2.4-h1 >= 11.1.0-h4, >= 11.1.1-h2, >= 11.1.2-h15, >= 11.1.3-h11, >= 11.1.4-h7, >= 11.1.5-h1 >= 11.0.0-h4, >= 11.0.1-h5, >= 11.0.2-h5, >= 11.0.3-h13, >= 11.0.4-h6, >= 11.0.5-h2, >= 11.0.6-h1 >= 10.2.0-h4, >= 10.2.1-h3, >= 10.2.2-h6, >= 10.2.3-h14, >= 10.2.4-h32, >= 10.2.5-h9, >= 10.2.6-h6, >= 10.2.7-h18, >= 10.2.8-h15, >= 10.2.9-h16, >= 10.2.10-h9, >= 10.2.11-h6, >= 10.2.12-h2 >= 10.1.3-h4, >= 10.1.6-h9, >= 10.1.8-h8, >= 10.1.9-h14, >= 10.1.10-h9, >= 10.1.11-h10, >= 10.1.12-h3, >= 10.1.13-h5, >= 10.1.14-h6 All | 2024-11-18 | 2024-11-21 |
1.3 | CVE-2024-5918
PAN-OS: Improper Certificate Validation Enables Impersonation of a Legitimate GlobalProtect User | Cloud NGFW PAN-OS 11.2 PAN-OS 11.1 PAN-OS 11.0 PAN-OS 10.2 PAN-OS 10.1 Prisma Access | None None None < 11.0.3 < 10.2.4-h5 < 10.1.11 None | All All All >= 11.0.3 >= 10.2.4-h5 >= 10.1.11 All | 2024-11-13 | 2024-11-13 |
6.6 | CVE-2024-2551
PAN-OS: Firewall Denial of Service (DoS) Using a Specially Crafted Packet | Cloud NGFW PAN-OS 11.2 PAN-OS 11.1 PAN-OS 11.0 PAN-OS 10.2 PAN-OS 10.1 Prisma Access | None None None < 11.0.5 < 10.2.4-h6, < 10.2.5 < 10.1.14 None | All All All >= 11.0.5 >= 10.2.4-h6, >= 10.2.5 >= 10.1.14 All | 2024-11-13 | 2024-11-13 |
0.5 | CVE-2024-5917
PAN-OS: Server-Side Request Forgery in WildFire | Cloud NGFW PAN-OS 11.2 PAN-OS 11.1 PAN-OS 11.0 PAN-OS 10.2 PAN-OS 10.1 | None None None None < 10.2.2 < 10.1.7 | All All All All >= 10.2.2 >= 10.1.7 | 2024-11-13 | 2025-01-22 |
1 | CVE-2024-5920
PAN-OS: Stored Cross-Site Scripting (XSS) Vulnerability in PAN-OS Enables Impersonation of a Legitimate Administrator | Cloud NGFW PAN-OS 11.2 PAN-OS 11.1 PAN-OS 11.0 PAN-OS 10.2 PAN-OS 10.1 Prisma Access | None None < 11.1.4 < 11.0.6 < 10.2.7-h24, < 10.2.10-h14, < 10.2.11 < 10.1.14 None | All All >= 11.1.4 >= 11.0.6 >= 10.2.7-h24, >= 10.2.10-h14, >= 10.2.11 >= 10.1.14 All | 2024-11-13 | 2025-04-30 |
1.2 | CVE-2024-5919
PAN-OS: Authenticated XML External Entities (XXE) Injection Vulnerability | Cloud NGFW PAN-OS 11.2 PAN-OS 11.1 PAN-OS 11.0 PAN-OS 10.2 PAN-OS 10.1 Prisma Access | None None None < 11.0.2 < 10.2.5 < 10.1.10 None | All All All >= 11.0.2 >= 10.2.5 >= 10.1.10 All | 2024-11-13 | 2024-11-13 |
5.1 | CVE-2024-9471
PAN-OS: Privilege Escalation (PE) Vulnerability in XML API | Cloud NGFW PAN-OS PAN-OS 11.0 PAN-OS 10.2 PAN-OS 10.1 Prisma Access | None 11.1 None, 9.1 All, 9.0 All < 11.0.3 < 10.2.8 < 10.1.11 None | All 11.1 All, 9.1 None, 9.0 None >= 11.0.3 >= 10.2.8 >= 10.1.11 All | 2024-10-09 | 2024-10-09 |
6.9 | CVE-2024-8687
PAN-OS: Cleartext Exposure of GlobalProtect Portal Passcodes | Cloud NGFW GlobalProtect App 6.3 GlobalProtect App 6.2 GlobalProtect App 6.1 GlobalProtect App 6.0 GlobalProtect App 5.2 GlobalProtect App 5.1 PAN-OS 11.2 PAN-OS 11.1 PAN-OS 11.0 PAN-OS 10.2 PAN-OS 10.1 PAN-OS 10.0 PAN-OS 9.1 PAN-OS 9.0 PAN-OS 8.1 Prisma Access | None None < 6.2.1 < 6.1.2 < 6.0.7 < 5.2.13 < 5.1.12 None None < 11.0.1 < 10.2.4 < 10.1.9 < 10.0.12 < 9.1.16 < 9.0.17 < 8.1.25 < 10.2.9 on PAN-OS | All All >= 6.2.1 >= 6.1.2 >= 6.0.7 >= 5.2.13 >= 5.1.12 All All >= 11.0.1 >= 10.2.4 >= 10.1.9 >= 10.0.12 >= 9.1.16 >= 9.0.17 >= 8.1.25 >= 10.2.9 on PAN-OS | 2024-09-11 | 2024-09-11 |
5.3 | CVE-2024-8691
PAN-OS: User Impersonation in GlobalProtect Portal | | None None None < 10.1.11 < 9.1.17 None | All All All >= 10.1.11 >= 9.1.17 all | 2024-09-11 | 2024-09-11 |
5.4 | CVE-2024-5913
PAN-OS: Improper Input Validation Vulnerability in PAN-OS | Cloud NGFW PAN-OS 11.2 PAN-OS 11.1 PAN-OS 11.0 PAN-OS 10.2 PAN-OS 10.1 Prisma Access | None < 11.2.1 < 11.1.4 < 11.0.5 < 10.2.10 < 10.1.14-h2 None | All >= 11.2.1 >= 11.1.4 >= 11.0.5 >= 10.2.10 >= 10.1.14-h2 All | 2024-07-10 | 2024-07-10 |
5.3 | CVE-2024-3596
PAN-OS: CHAP and PAP When Used with RADIUS Authentication Lead to Privilege Escalation | Cloud NGFW PAN-OS 11.2 PAN-OS 11.1 PAN-OS 11.0 PAN-OS 10.2 PAN-OS 10.1 PAN-OS 9.1 Prisma Access | None None < 11.1.3 < 11.0.4-h5, < 11.0.6 < 10.2.4-h21, < 10.2.7-h21, < 10.2.8-h20, < 10.2.9-h8, < 10.2.10 < 10.1.12-h4, < 10.1.14 < 9.1.19 None | All All >= 11.1.3 >= 11.0.4-h5, >= 11.0.6 >= 10.2.4-h21, >= 10.2.7-h21, >= 10.2.8-h20, >= 10.2.9-h8, >= 10.2.10 >= 10.1.12-h4, >= 10.1.14 >= 9.1.19 All | 2024-07-10 | 2025-04-30 |
7 | CVE-2024-5911
PAN-OS: File Upload Vulnerability in the Panorama Web Interface | | None None None < 10.2.4 on Panorama < 10.1.9 on Panorama None | All All All >= 10.2.4 on Panorama >= 10.1.9 on Panorama all | 2024-07-10 | 2024-07-10 |
6.9 | CVE-2024-3386
PAN-OS: Predefined Decryption Exclusions Does Not Work as Intended | Cloud NGFW PAN-OS 11.1 PAN-OS 11.0 PAN-OS 10.2 PAN-OS 10.1 PAN-OS 10.0 PAN-OS 9.1 PAN-OS 9.0 Prisma Access | None None < 11.0.1-h2, < 11.0.2 < 10.2.4-h2, < 10.2.5 < 10.1.9-h3, < 10.1.10 < 10.0.13 < 9.1.17 < 9.0.17-h2 None | All All >= 11.0.1-h2, >= 11.0.2 >= 10.2.4-h2, >= 10.2.5 >= 10.1.9-h3, >= 10.1.10 >= 10.0.13 >= 9.1.17 >= 9.0.17-h2 All | 2024-04-10 | 2024-04-10 |