Wednesday, 09 July 2025

Palo Alto Networks patches flaws in its products

Palo Alto Networks announced the availability of patches to address security flaws in the GlobalProtect App, Cortex XSOAR and PAN-OS. Updates fix the following issues:

CVE-2022-0016 - privilege escalation vulnerability in the Palo Alto Networks GlobalProtect app;

CVE-2022-0017 – security vulnerability in the Palo Alto Networks GlobalProtect app on Windows that enables a local attacker to disrupt system processes and potentially execute arbitrary code with SYSTEM privileges;

CVE-2022-0020 - Cross-Site Scripting (XSS) vulnerability in Palo Alto Network Cortex XSOAR web interface;

CVE-2022-0011 – security vulnerability in the PAN-OS;

CVE-2022-0018 - An information exposure vulnerability in the Palo Alto Networks GlobalProtect app on Windows and MacOS;

CVE-2022-0019 - An insufficiently protected credentials vulnerability in the Palo Alto Networks GlobalProtect app on Linux;

CVE-2022-0021 - An information exposure vulnerability in the Palo Alto Networks GlobalProtect app on Windows.

More information on vulnerabilities and updates is available in Palo Alto Networks security advisories – paloaltonetworks.com.

14 February 2022

-
80