PA-5020
Announced in: PA-5000 Series
Chassis
· PA-5000 Series
Known Exploited Vulnerabilities
This device is past Palo Alto's security-support date. 10 CVEs in CISA's Known Exploited Vulnerabilities catalog apply to the platform it runs. Palo Alto is not issuing patches for this model. Isolate, compensate, or refresh.
| CVE | KEV added | Vulnerability | Flags |
|---|---|---|---|
CVE-2025-0111
|
Palo Alto Networks PAN-OS File Read Vulnerability | ||
CVE-2025-0108
|
Palo Alto Networks PAN-OS Authentication Bypass Vulnerability | ||
CVE-2024-3393
|
Palo Alto Networks PAN-OS Malicious DNS Packet Vulnerability | ||
CVE-2024-9474
|
Palo Alto Networks PAN-OS Management Interface OS Command Injection Vulnerability | Ransomware | |
CVE-2024-0012
|
Palo Alto Networks PAN-OS Management Interface Authentication Bypass Vulnerability | Ransomware | |
CVE-2024-3400
|
Palo Alto Networks PAN-OS Command Injection Vulnerability | Ransomware | |
CVE-2022-0028
|
Palo Alto Networks PAN-OS Reflected Amplification Denial-of-Service Vulnerability | ||
CVE-2017-15944
|
Palo Alto Networks PAN-OS Remote Code Execution Vulnerability | ||
CVE-2020-2021
|
Palo Alto Networks PAN-OS Authentication Bypass Vulnerability | Ransomware | |
CVE-2019-1579
|
Palo Alto Networks PAN-OS Remote Code Execution Vulnerability | Ransomware |
Source: CISA Known Exploited Vulnerabilities catalog. The Ransomware flag reflects CISA's own knownRansomwareCampaignUse field, set when the CVE has been observed in ransomware campaigns per their threat intel. It's not a property of the vulnerability description itself.
Correlation is at the platform level, not per-OS-version. Not exhaustive: KEV only lists actively-exploited CVEs and many relevant unexploited vulnerabilities are not here. Verify against vendor security advisories (PSIRT, JSA, PAN-SA) and NVD before acting. See compensating controls if refresh isn't immediate.
PA-5020 Lifecycle Overview
The Palo Alto PA-5020 (PA-5020) is a chassis product in the Palo Alto PA-5000 series. This product has reached end of life as of , meaning Palo Alto no longer provides technical support, software updates, or hardware replacement for this product. It was last available for purchase on . Organizations still running the PA-5020 should plan a migration to PA-5400 Series, PA-5500 Series.
Lifecycle Milestones
| End of sale | 7y 3mo ago | |
|---|---|---|
| Last date of support | 2y 3mo ago |
PAN-OS 8.1