
CVE-2012-6597
https://notcve.org/view.php?id=CVE-2012-6597
31 Aug 2013 — Palo Alto Networks PAN-OS before 3.1.11 and 4.0.x before 4.0.9 allows remote authenticated users to cause a denial of service (management-server crash) by using the command-line interface for a crafted command, aka Ref ID 35254. Palo Alto Networks PAN-OS anterior a 3.1.11 y 4.0.x anterior a 4.0.9, permite a usuarios autenticados remotamente provocar una denegación de servicio (caída del servidor de administración) utilizando un comando manipulado desde la interfaz. Aka Ref ID 35254. • https://security.paloaltonetworks.com/CVE-2012-6597 • CWE-20: Improper Input Validation •

CVE-2012-6605
https://notcve.org/view.php?id=CVE-2012-6605
31 Aug 2013 — The device-management command-line interface in Palo Alto Networks PAN-OS before 3.1.11 and 4.0.x before 4.0.9 allows remote authenticated users to execute arbitrary code via unspecified vectors, aka Ref ID 34896. La administración del dispositivo mediante el interfaz de comandos en Palo Alto Networks PAN-OS anterior a 3.1.11 y 4.0.x anterior a 4.0.9, permite a usuarios autenticados remotamente ejecutar comandos arbitrarios a través de vectores sin especificar. Aka Ref ID 34896. • https://security.paloaltonetworks.com/CVE-2012-6605 • CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') •

CVE-2013-5663
https://notcve.org/view.php?id=CVE-2013-5663
31 Aug 2013 — The App-ID cache feature in Palo Alto Networks PAN-OS before 4.0.14, 4.1.x before 4.1.11, and 5.0.x before 5.0.2 allows remote attackers to bypass intended security policies via crafted requests that trigger invalid caching, as demonstrated by incorrect identification of HTTP traffic as SIP traffic, aka Ref ID 47195. La característica App-ID cache en Palo Alto Networks PAN-OS anterior a 4.0.14, 4.1.x anterior a 4.1.11 y 5.0.x anterior a 5.0.2, permite a atacantes remotos evitar las políticas de seguridad es... • http://cansecwest.com/csw11/Network%20Application%20FW%20vs.%20Contemporary%20Threats%20%28Brad%20Woodberg%20-%20Final%29.pptx • CWE-264: Permissions, Privileges, and Access Controls •

CVE-2012-6601
https://notcve.org/view.php?id=CVE-2012-6601
31 Aug 2013 — The device-management command-line interface in Palo Alto Networks PAN-OS before 3.1.12, 4.0.x before 4.0.10, and 4.1.x before 4.1.4 allows remote attackers to execute arbitrary code via unspecified vectors, aka Ref ID 36983. La gestión del dispositivo a través del interfaz de comandos en Palo Alto Networks PAN-OS anterior a 3.1.12,y 4.0.x anterior a 4.0.10, y 4.1.x anterior a 4.1.4, permite a usuarios autenticados remotamente ejecutar comandos arbitrarios a través de vectores no especificados. Aka Ref ID 3... • https://security.paloaltonetworks.com/CVE-2012-6601 • CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') •

CVE-2012-6590
https://notcve.org/view.php?id=CVE-2012-6590
31 Aug 2013 — The web-based management UI in Palo Alto Networks PAN-OS 4.0.x before 4.0.8 allows remote attackers to obtain verbose error information via crafted input, aka Ref ID 33139. La aplicación de gestión web UI de Palo Alto Networks PAN-OS 4.0.x anterior a 4.0.8 permite a atacantes remotos obtener información de errores a través de datos de entrada manipulados. Aka Ref ID 33139. • https://security.paloaltonetworks.com/CVE-2012-6590 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVE-2012-6604
https://notcve.org/view.php?id=CVE-2012-6604
31 Aug 2013 — The device-management command-line interface in Palo Alto Networks PAN-OS before 3.1.11 and 4.0.x before 4.0.9 allows remote authenticated users to execute arbitrary code via unspecified vectors, aka Ref ID 35249. La gestión del dispositivo a través del interfaz de comandos en Palo Alto Networks PAN-OS anterior a 3.1.11 y 4.0x anterior a 4.0.9, permite a usuarios autenticados remotamente ejecutar comandos arbitrarios a través de vectores no especificados. Aka Ref ID 35249. • https://security.paloaltonetworks.com/CVE-2012-6604 • CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') •

CVE-2012-6595
https://notcve.org/view.php?id=CVE-2012-6595
31 Aug 2013 — The device-management command-line interface in Palo Alto Networks PAN-OS 4.0.x before 4.0.9 and 4.1.x before 4.1.2 allows remote authenticated administrators to execute arbitrary commands via unspecified vectors, aka Ref ID 34595. La administración del dispositivo mediante el interfaz de comandos en Palo Alto Networks PAN-OS 4.0.x anterior a 4.0.9 y 4.1.x anterior a 4.1.2, permite a usuarios autenticados remotamente ejecutar comandos arbitrarios a través de vectores sin especificar. Aka Ref ID 34595. • https://security.paloaltonetworks.com/CVE-2012-6595 • CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') •

CVE-2012-6596
https://notcve.org/view.php?id=CVE-2012-6596
31 Aug 2013 — Palo Alto Networks PAN-OS 4.0.x before 4.0.9 and 4.1.x before 4.1.3 stores cleartext LDAP bind passwords in authd.log, which allows context-dependent attackers to obtain sensitive information by reading this file, aka Ref ID 35493. Palo Alto Networks PAN-OS anterior a 4.0.9 y 4.1.x anterior a 4.1.3, almacena en texto calro las contraseñas LDAP bind en authd.log, lo que permite a atacantes dependientes del contexto obtener información sensible mediante la lectura de ese archivo. Aka Ref ID 35493. • https://security.paloaltonetworks.com/CVE-2012-6596 • CWE-255: Credentials Management Errors •

CVE-2012-6599
https://notcve.org/view.php?id=CVE-2012-6599
31 Aug 2013 — The device-management command-line interface in Palo Alto Networks PAN-OS 4.0.x before 4.0.8 and 4.1.x before 4.1.1 allows remote authenticated users to execute arbitrary commands via unspecified vectors, aka Ref ID 33476. La administración del dispositivo mediante el interfaz de comandos en Palo Alto Networks PAN-OS 4.0.x anterior a 4.0.8 y 4.1.x anterior a 4.1.1, permite a usuarios autenticados remotamente ejecutar comandos arbitrarios a través de vectores sin especificar. Aka Ref ID 34502. • https://security.paloaltonetworks.com/CVE-2012-6599 • CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') •

CVE-2012-6600
https://notcve.org/view.php?id=CVE-2012-6600
31 Aug 2013 — The device-management command-line interface in Palo Alto Networks PAN-OS 4.0.x before 4.0.9 and 4.1.x before 4.1.2 allows remote authenticated users to execute arbitrary commands via unspecified vectors, aka Ref ID 34502. La administración del dispositivo mediante el interfaz de comandos en Palo Alto Networks PAN-OS 4.0.x anterior a 4.0.9 y 4.1.x anterior a 4.1.2, permite a usuarios autenticados remotamente ejecutar comandos arbitrarios a través de vectores sin especificar. Aka Ref ID 34502. • https://security.paloaltonetworks.com/CVE-2012-6600 • CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') •