#VU27898 Improper Authorization in Palo Alto PAN-OS - CVE-2020-1998
Published: May 14, 2020
Palo Alto PAN-OS
Palo Alto Networks, Inc.
Description
The vulnerability allows a remote user to gain elevated privileges on the system.
The vulnerability exists within SAML SSO in PAN-OS that mistakenly uses the permissions of local Linux users
instead of the intended SAML permissions of the account when the
username is shared for the purposes of SSO authentication. A remote user can escalate privileges on the system.