« Volver al listado

Paloaltonetworks

Paloaltonetworks Prisma Access: vulnerabilidades y CVE

Paloaltonetworks Prisma Access tiene 11 vulnerabilidades publicadas, 4 de ellas en los últimos 12 meses. 0 son críticas y 2 figuran en el catálogo de explotación activa de CISA.

CVE11
Últimos 12 meses4
Críticas0
Explotadas activamente2

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

🔴 Explotadas activamente (CISA KEV)

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-0257Alta (7.8)97%⚠ Explotación activa13 may 2026
Authentication bypass vulnerabilities in the GlobalProtect portal and gateway of Palo Alto Networks PAN-OS® software allows the attacker to bypass security restrictions and establish an unauthorized VPN connection.…
CVE-2024-3393Alta (8.7)29%⚠ Explotación activa27 dic 2024
A Denial of Service vulnerability in the DNS Security feature of Palo Alto Networks PAN-OS software allows an unauthenticated attacker to send a malicious packet through the data plane of the firewall that reboots the…

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-0301Baja (1.7)0.32%—13 ago 2026
An information disclosure vulnerability in the URL Filtering feature of Palo Alto Networks PAN-OS® software enables an unauthenticated user with network access to obtain sensitive information. Panorama is not impacted…
CVE-2026-0257Alta (7.8)97%⚠ Explotación activa13 may 2026
Authentication bypass vulnerabilities in the GlobalProtect portal and gateway of Palo Alto Networks PAN-OS® software allows the attacker to bypass security restrictions and establish an unauthorized VPN connection.…
CVE-2026-0227Media (6.6)0.75%—15 ene 2026
A vulnerability in Palo Alto Networks PAN-OS software enables an unauthenticated attacker to cause a denial of service (DoS) to the firewall. Repeated attempts to trigger this issue results in the firewall entering into…
CVE-2025-4619Media (6.6)0.56%—13 nov 2025
A denial-of-service (DoS) vulnerability in Palo Alto Networks PAN-OS software enables an unauthenticated attacker to reboot a firewall by sending a specially crafted packet through the dataplane. Repeated attempts to…
CVE-2025-0126Alta (8.3)0.40%—11 abr 2025
When configured using SAML, a session fixation vulnerability in the GlobalProtect™ login enables an attacker to impersonate a legitimate authorized user and perform actions as that GlobalProtect user. This requires the…
CVE-2024-3393Alta (8.7)29%⚠ Explotación activa27 dic 2024
A Denial of Service vulnerability in the DNS Security feature of Palo Alto Networks PAN-OS software allows an unauthenticated attacker to send a malicious packet through the data plane of the firewall that reboots the…
CVE-2024-8687Media (6.9)0.41%—11 sept 2024
An information exposure vulnerability exists in Palo Alto Networks PAN-OS software that enables a GlobalProtect end user to learn both the configured GlobalProtect uninstall password and the configured disable or…
CVE-2024-3388Media (5)0.35%—10 abr 2024
A vulnerability in the GlobalProtect Gateway in Palo Alto Networks PAN-OS software enables an authenticated attacker to impersonate another user and send network packets to internal assets. However, this vulnerability…
CVE-2022-0011Media (6.5)0.66%—10 feb 2022
PAN-OS software provides options to exclude specific websites from URL category enforcement and those websites are blocked or allowed (depending on your rules) regardless of their associated URL category. This is done…
CVE-2021-3061Alta (7.2)0.86%—10 nov 2021
An OS command injection vulnerability in the Palo Alto Networks PAN-OS command line interface (CLI) enables an authenticated administrator with access to the CLI to execute arbitrary OS commands to escalate privileges.…
CVE-2021-3060Alta (8.1)33%—10 nov 2021
An OS command injection vulnerability in the Simple Certificate Enrollment Protocol (SCEP) feature of PAN-OS software allows an unauthenticated network-based attacker with specific knowledge of the firewall…

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1190 Exploit Public-Facing Application2
  2. T1078.001 Default Accounts1
  3. T1078.002 Domain Accounts1
  4. T1203 Exploitation for Client Execution1
  5. T1499.004 Application or System Exploitation1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Paloaltonetworks