Improper Authentication in Palo Alto PAN-OS - CVE-2020-2018
Published: May 14, 2020
Palo Alto PAN-OS
Palo Alto Networks, Inc.
Description
The vulnerability allows a remote attacker to bypass authentication process.
The vulnerability exists due to insecure registration mechanism in Palo Alto Networks PAN-OS Panorama proxy service. A remote attacker with network access to the Panorama and the knowledge of the Firewall’s serial number can register the PAN-OS firewall and gain full access to the device.