Cleartext transmission of sensitive information in Palo Alto PAN-OS - CVE-2020-2013

 

Cleartext transmission of sensitive information in Palo Alto PAN-OS - CVE-2020-2013

Published: May 14, 2020


Vulnerability identifier: #VU27887
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-2013
CWE-ID: CWE-319
Exploitation vector: Adjecent network
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain access to sensitive information.

The vulnerability exists due to software uses insecure communication channel to transmit sensitive information in Palo Alto Networks PAN-OS Panoramathat discloses an authenticated PAN-OS administrator's PAN-OS session cookie. When an administrator issues a context switch request into a managed firewall with an affected PAN-OS Panorama version, their PAN-OS session cookie is transmitted over cleartext to the firewall. An attacker with the ability to intercept this network traffic between the firewall and Panorama can access the administrator's account and further manipulate devices managed by Panorama.


Affected software

Palo Alto PAN-OS

How to mitigate CVE-2020-2013

Install updates from vendor's website.

Palo Alto PAN-OS - addressed in versions 7.1.26, 8.1.13, 9.0.6, 9.1.1

External References

Related Security Bulletins