Known vulnerabilities in Palo Alto PAN-OS - page 8

Software CPE: cpe:2.3:o:palo_alto_networks:pan-os:*:*:*:*:*:*:*:*
Total vulnerabilities: 254
Public exploits: 20
Known exploited (KEV): 12
Highest CVSSv4 Score: 10

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting Palo Alto PAN-OS Palo Alto PAN-OS is affected by 254 known vulnerabilities: 9 critical, 40 high, 76 medium, 129 low Critical High Medium Low

Vulnerabilities (254)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU46576 - Memory corruption
CVE-2020-2040
CWE-119 High
No
No
8.1.15, 9.0.9, 9.1.3 10.09.2020 SB2020091017
#VU46574 - Resource exhaustion
CVE-2020-2039
CWE-400 High
No
No
8.1.16, 9.0.10, 9.1.4, 10.0.1 10.09.2020 SB2020091015
#VU46557 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2020-2038
CWE-78 Medium
Available
No
9.0.10, 9.1.4, 10.0.1 10.09.2020 SB2020091014
#VU46556 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2020-2037
CWE-78 Medium
No
No
8.1.16, 9.0.10, 9.1.3 10.09.2020 SB2020091013
#VU46555 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2020-2036
CWE-79 Low
No
No
8.1.16, 9.0.9 10.09.2020 SB2020091012
#VU45651 - Improper input validation
CVE-2020-2035
CWE-20 Medium
No
No
- 12.08.2020 SB2020081269
#VU29608 - Cryptographic Issues
CVE-2020-1982
CWE-310 Low
No
No
8.1.15, 9.0.9, 9.1.3 09.07.2020 SB2020070908
#VU29607 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2020-2030
CWE-78 Low
No
No
8.1.15 09.07.2020 SB2020070907
#VU29606 - Integer underflow
CVE-2020-2031
CWE-191 Low
No
No
9.1.3 09.07.2020 SB2020070906
#VU29605 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2020-2034
CWE-78 Critical
Available
No
8.1.15, 9.0.9, 9.1.3 09.07.2020 SB2020070905
#VU29387 - Improper Authentication
CVE-2020-2021
CWE-287 High
Available
Exploited
8.1.15, 9.0.9, 9.1.3 30.06.2020 SB2020063004
#VU28958 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2020-2029
CWE-78 Low
No
No
7.1.26, 8.1.13 11.06.2020 SB2020061101
#VU28957 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2020-2028
CWE-78 Low
No
No
8.1.13, 9.0.7 10.06.2020 SB2020061101
#VU28956 - Stack-based buffer overflow
CVE-2020-2027
CWE-121 Low
No
No
8.1.13, 9.0.7 10.06.2020 SB2020061101
#VU27950 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVE-2020-2016
CWE-362 Low
No
No
7.1.26, 8.1.13, 9.0.6, 9.1.0, 9.2.0 15.05.2020 SB2020051518
#VU27949 - Improper input validation
CVE-2020-2011
CWE-20 Medium
No
No
8.1.14, 9.0.7, 9.1.0 15.05.2020 SB2020051518
#VU27903 - Session Fixation
CVE-2020-1993
CWE-384 Medium
No
No
8.1.14, 9.0.8 14.05.2020 SB2020051401
#VU27902 - Permissions, Privileges, and Access Controls
CVE-2020-1994
CWE-264 Low
No
No
8.1.13, 9.0.7 14.05.2020 SB2020051401
#VU27901 - NULL Pointer Dereference
CVE-2020-1995
CWE-476 Low
No
No
9.1.2 14.05.2020 SB2020051401
#VU27900 - Improper Authorization
CVE-2020-1996
CWE-285 Medium
No
No
8.1.14, 9.0.9 14.05.2020 SB2020051401


Showing elements 141 - 160 out of 254