Improper Authorization in Palo Alto PAN-OS - CVE-2020-1996

 

Improper Authorization in Palo Alto PAN-OS - CVE-2020-1996

Published: May 14, 2020


Vulnerability identifier: #VU27900
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-1996
CWE-ID: CWE-285
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass authorization and manipulate log files.

The vulnerability exists in the management server component of PAN-OS Panorama. A remote non-authenticated attacker can send a specially crafted request to the system and inject messages into the management server ms.log file.

Successful exploitation of the vulnerability may allow an attacker to obfuscate log files and hide malicious presence on the system.


Affected software

Palo Alto PAN-OS

How to mitigate CVE-2020-1996

Install updates from vendor's website.

Palo Alto PAN-OS - addressed in versions 8.1.14, 9.0.9

External References

Related Security Bulletins