Skip to main content
0-Doubt
NewsInvestorsQuestionnairesDeveloperHelp
AnonymousSign in
0-Doubt — neutral IT/Security research
BrowseResellersCertified analystsRFI/RFP questionnairesHow trust worksHelp & FAQAPI
  1. Home/
  2. Palo Alto Networks/
  3. Palo Alto Networks Prisma Cloud

Palo Alto Networks Prisma Cloud

AI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Secure coding rating: 0/100How this score is computedA product with no known CVEs starts at a neutral score and climbs the longer it goes without one; a product with known CVEs is penalized by severity instead. This one has 100 known CVEs (vendor-level match — see the CVE list below) and is tracked as ~39 days old in our catalog (a stand-in for real release date, which we don't track). The platform admin controls the formula's weights.

Code to cloud security platform for app lifecycle protection

by Palo Alto Networks · paloaltonetworks.com · source ↗

Known CVEs (100)About this listSourced from the public NVD database, matched by vendor name. Shown here at the vendor level — we don't track per-product/version data, so a listed CVE may affect a different product from this vendor, not necessarily this one. “New” means published within the last 30 days. “Actively exploited” means CISA's Known Exploited Vulnerabilities (KEV) catalog confirms real-world exploitation, not just a theoretical severity score.

RSS ⇢
  • CVE-2020-2049 ↗HIGH 7.82020

    A local privilege escalation vulnerability exists in Palo Alto Networks Cortex XDR Agent on the Windows platform that allows an authenticated local Windows user to execute programs with SYSTEM privile…

  • CVE-2020-2050 ↗HIGH 8.22020

    An authentication bypass vulnerability exists in the GlobalProtect SSL VPN component of Palo Alto Networks PAN-OS software that allows an attacker to bypass all client certificate checks with an inval…

  • CVE-2020-2048 ↗LOW 3.32020

    An information exposure through log file vulnerability exists where the password for the configured system proxy server for a PAN-OS appliance may be displayed in cleartext when using the CLI in Palo …

  • CVE-2020-2022 ↗HIGH 7.52020

    An information exposure vulnerability exists in Palo Alto Networks Panorama software that discloses the token for the Panorama web interface administrator's session to a managed device when the Panora…

  • CVE-2020-2044 ↗LOW 3.32020

    An information exposure through log file vulnerability where an administrator's password or other sensitive information may be logged in cleartext while using the CLI in Palo Alto Networks PAN-OS soft…

  • CVE-2020-2043 ↗LOW 3.32020

    An information exposure through log file vulnerability where sensitive fields are recorded in the configuration log without masking on Palo Alto Networks PAN-OS software when the after-change-detail c…

  • CVE-2020-2041 ↗HIGH 7.52020

    An insecure configuration of the appweb daemon of Palo Alto Networks PAN-OS 8.1 allows a remote unauthenticated user to send a specifically crafted request to the device that causes the appweb service…

  • CVE-2020-2039 ↗MEDIUM 5.32020

    An uncontrolled resource consumption vulnerability in Palo Alto Networks PAN-OS allows for a remote unauthenticated user to upload temporary files through the management web interface that are not pro…

  • CVE-2020-2035 ↗LOW 3.02020

    When SSL/TLS Forward Proxy Decryption mode has been configured to decrypt the web transactions, the PAN-OS URL filtering feature inspects the HTTP Host and URL path headers for policy enforcement on t…

  • CVE-2020-2021 ↗⚠ actively exploitedCRITICAL 10.02020

    When Security Assertion Markup Language (SAML) authentication is enabled and the 'Validate Identity Provider Certificate' option is disabled (unchecked), improper verification of signatures in PAN-OS …

  • CVE-2020-2033 ↗MEDIUM 5.32020

    When the pre-logon feature is enabled, a missing certification validation in Palo Alto Networks GlobalProtect app can disclose the pre-logon authentication cookie to a man-in-the-middle attacker on th…

  • CVE-2020-2032 ↗HIGH 7.02020

    A race condition vulnerability Palo Alto Networks GlobalProtect app on Windows allows a local limited Windows user to execute programs with SYSTEM privileges. This issue can be exploited only while pe…

  • CVE-2020-2013 ↗HIGH 8.32020

    A cleartext transmission of sensitive information vulnerability in Palo Alto Networks PAN-OS Panorama that discloses an authenticated PAN-OS administrator's PAN-OS session cookie. When an administrato…

  • CVE-2020-2012 ↗HIGH 7.52020

    Improper restriction of XML external entity reference ('XXE') vulnerability in Palo Alto Networks Panorama management service allows remote unauthenticated attackers with network access to the Panoram…

  • CVE-2020-2011 ↗HIGH 7.52020

    An improper input validation vulnerability in the configuration daemon of Palo Alto Networks PAN-OS Panorama allows for a remote unauthenticated user to send a specifically crafted registration reques…

  • CVE-2020-2009 ↗HIGH 7.22020

    An external control of filename vulnerability in the SD WAN component of Palo Alto Networks PAN-OS Panorama allows an authenticated administrator to send a request that results in the creation and wri…

  • CVE-2020-2008 ↗HIGH 7.22020

    An OS command injection and external control of filename vulnerability in Palo Alto Networks PAN-OS allows authenticated administrators to execute code with root privileges or delete arbitrary system …

  • CVE-2020-2005 ↗HIGH 7.12020

    A cross-site scripting (XSS) vulnerability exists when visiting malicious websites with the Palo Alto Networks GlobalProtect Clientless VPN that can compromise the user's active session. This issue af…

  • CVE-2020-2004 ↗MEDIUM 6.82020

    Under certain circumstances a user's password may be logged in cleartext in the PanGPS.log diagnostic file when logs are collected for troubleshooting on GlobalProtect app (also known as GlobalProtect…

  • CVE-2020-2002 ↗HIGH 8.12020

    An authentication bypass by spoofing vulnerability exists in the authentication daemon and User-ID components of Palo Alto Networks PAN-OS by failing to verify the integrity of the Kerberos key distri…

  • …and 80 more

Materials

0

No datasheets, whitepapers, case studies, videos, or demos linked yet.

Other Cloud-Native Application Protection (CNAPP) products

see all →
  • ARMO · ARMO
  • ARMO Cloud Application Detection & Response · ARMO
  • ARMO Continuous Cloud Security Posture Management · ARMO
  • ARMO Kubernetes Security Posture Management · ARMO
  • ARMO Runtime-based Cloud Hardening & Remediation · ARMO
  • ARMO Vulnerability Management · ARMO
  • AccuKnox 5G Security (5GNAPP) · AccuKnox
  • AccuKnox Application Security · AccuKnox