Palo Alto Luki w zabezpieczeniach

Oś czasu

Rodzaj

Produkt

Palo Alto PAN-OS175
Palo Alto Networks PAN-OS22
Palo Alto GlobalProtect App15
Palo Alto Networks Cloud NGFW14
Palo Alto Networks Prisma Access14

Przeciwdziałanie

Official Fix232
Temporary Fix0
Workaround0
Unavailable1
Not Defined40

Wykorzystywanie

High9
Functional0
Proof-of-Concept19
Unproven1
Not Defined244

Wektor dostępu

Not Defined0
Physical2
Local49
Adjacent2
Network220

Uwierzytelnianie

Not Defined0
High46
Low127
None100

Interakcja z użytkownikiem

Not Defined0
Required45
None228

CVSSv3 Base

≤10
≤20
≤39
≤428
≤545
≤658
≤748
≤849
≤925
≤1011

CVSSv3 Temp

≤10
≤20
≤310
≤433
≤551
≤651
≤762
≤835
≤920
≤1011

VulDB

≤10
≤22
≤317
≤437
≤552
≤655
≤732
≤847
≤920
≤1011

NVD

≤10
≤20
≤31
≤44
≤515
≤619
≤728
≤837
≤913
≤1017

CNA

≤10
≤20
≤31
≤42
≤515
≤614
≤723
≤812
≤910
≤104

Sprzedawca

≤10
≤20
≤31
≤40
≤51
≤60
≤70
≤80
≤90
≤101

Research

≤10
≤20
≤30
≤40
≤50
≤60
≤70
≤80
≤90
≤100

Exploit 0-day

<1k75
<2k90
<5k105
<10k0
<25k1
<50k0
<100k1
≥100k1

Wykorzystaj dzisiaj

<1k266
<2k5
<5k0
<10k0
<25k1
<50k1
<100k0
≥100k0

Affected Products (27): ActiveMQ Content Pack (1), Cloud NGFW (19), Cortex XDR Agent (19), Cortex XSOAR (9), Cortex XSOAR CommonScripts (1), Demisto (1), Expedition (1), Expedition Migration Tool (2), Firewall (1), GlobalProtect (1), Global Protect Agent (2), GlobalProtect Agent (3), GlobalProtect App (17), Global Protected Gateway (1), MineMeld (1), NetConnect (1), Network Traps ESM Console (1), Networks Global Protect Agent (1), Networks Twistlock (1), PAN-OS (197), Prisma Access (19), Prisma Cloud Compute (4), Terminal Services Agent (3), Traps (2), Traps Server (1), VM Series Firewall for Microsoft Azure (1), Web Interface (2)

OpublikowanoBaseTempSłaby punktProdWykPrzEPSSCTICVE
2024-09-113.73.6Palo Alto Networks ActiveMQ Content Pack weak encryptionNieznanyNot DefinedOfficial Fix0.000430.03CVE-2024-8689
2024-09-114.24.0Palo Alto Networks Cortex XDR Agent Detection Mechanism Local Privilege EscalationNieznanyNot DefinedOfficial Fix0.000430.05CVE-2024-8690
2024-09-115.35.1Palo Alto Networks PAN-OS/GlobalProtect App/Cloud NGFW/Prisma Access Configuration Local Privilege EscalationFirewall SoftwareNot DefinedOfficial Fix0.000430.00CVE-2024-8687
2024-09-117.26.9Palo Alto Networks PAN-OS/Cloud NGFW/Prisma Access privilege escalationFirewall SoftwareNot DefinedOfficial Fix0.000430.03CVE-2024-8686
2024-09-116.36.0Palo Alto Networks PAN-OS/Cloud NGFW/Prisma Access GlobalProtect Portal privilege escalationFirewall SoftwareNot DefinedOfficial Fix0.000430.04CVE-2024-8691
2024-09-112.32.2Palo Alto Networks PAN-OS/Cloud NGFW/Prisma Access Command Line Interface information disclosureFirewall SoftwareNot DefinedOfficial Fix0.000430.04CVE-2024-8688
2024-08-147.87.6Palo Alto GlobalProtect App privilege escalationNieznanyNot DefinedOfficial Fix0.000430.00CVE-2024-5915
2024-08-147.77.6Palo Alto Cortex XSOAR CommonScripts privilege escalationNieznanyNot DefinedOfficial Fix0.000900.02CVE-2024-5914
2024-08-143.33.3Palo Alto PAN-OS/Cloud NGFW/Prisma Access information disclosureFirewall SoftwareNot DefinedOfficial Fix0.000430.04CVE-2024-5916
2024-07-106.26.0Palo Alto Networks PAN-OS/Cloud NGFW/Prisma Access Physical File System privilege escalationFirewall SoftwareNot DefinedOfficial Fix0.000430.03CVE-2024-5913
2024-07-105.35.1Palo Alto Networks Cortex XDR Agent weak authenticationNieznanyNot DefinedOfficial Fix0.000430.02CVE-2024-5912
2024-07-107.26.9Palo Alto Networks PAN-OS/Cloud NGFW/Prisma Access privilege escalationFirewall SoftwareNot DefinedOfficial Fix0.000430.04CVE-2024-5911
2024-07-109.89.4Palo Alto Networks Expedition weak authenticationNieznanyNot DefinedOfficial Fix0.000430.04CVE-2024-5910
2024-06-123.33.2Palo Alto Networks GlobalProtect App information disclosureNieznanyNot DefinedOfficial Fix0.000870.04CVE-2024-5908
2024-06-122.42.3Palo Alto Networks Prisma Cloud Compute Web Interface cross site scriptingCloud SoftwareNot DefinedOfficial Fix0.000450.03CVE-2024-5906
2024-06-123.33.2Palo Alto Networks Cortex XDR Agent privilege escalationNieznanyNot DefinedOfficial Fix0.000430.04CVE-2024-5909
2024-06-124.54.3Palo Alto Networks Cortex XDR Agent privilege escalationNieznanyNot DefinedOfficial Fix0.000430.00CVE-2024-5907
2024-06-123.33.2Palo Alto Networks Cortex XDR Agent privilege escalationNieznanyNot DefinedOfficial Fix0.000430.03CVE-2024-5905
2024-04-128.98.7Palo Alto Networks PAN-OS GlobalProtect privilege escalationFirewall SoftwareHighOfficial Fix0.964640.00CVE-2024-3400
2024-04-104.54.4Palo Alto Networks PAN-OS weak encryptionFirewall SoftwareNot DefinedOfficial Fix0.000430.04CVE-2024-3387
2024-04-104.84.7Palo Alto Networks PAN-OS GlobalProtect Gateway privilege escalationFirewall SoftwareNot DefinedOfficial Fix0.000430.00CVE-2024-3388
2024-04-105.35.2Palo Alto Networks PAN-OSFirewall SoftwareNot DefinedOfficial Fix0.000430.04CVE-2024-3386
2024-04-107.57.3Palo Alto Networks PAN-OS Packets denial of serviceFirewall SoftwareNot DefinedOfficial Fix0.000430.00CVE-2024-3382
2024-04-107.57.3Palo Alto Networks PAN-OS Packet denial of serviceFirewall SoftwareNot DefinedOfficial Fix0.000430.06CVE-2024-3385
2024-04-106.16.0Palo Alto Networks PAN-OS Cloud Identity EngineFirewall SoftwareNot DefinedOfficial Fix0.000430.00CVE-2024-3383

248 więcej wpisów nie jest pokazywanych

Do you want to use VulDB in your project?

Use the official API to access entries easily!