#VU27887 Cleartext transmission of sensitive information in Palo Alto PAN-OS - CVE-2020-2013

 

#VU27887 Cleartext transmission of sensitive information in Palo Alto PAN-OS - CVE-2020-2013

Published: May 14, 2020


Vulnerability identifier: #VU27887
Vulnerability risk: Low
CVSSv4.0: CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2020-2013
CWE-ID: CWE-319
Exploitation vector: Adjecent network
Exploit availability: No public exploit available
Vulnerable software:
Palo Alto PAN-OS
Software vendor:
Palo Alto Networks, Inc.

Description

The vulnerability allows a remote attacker to gain access to sensitive information.

The vulnerability exists due to software uses insecure communication channel to transmit sensitive information in Palo Alto Networks PAN-OS Panoramathat discloses an authenticated PAN-OS administrator's PAN-OS session cookie. When an administrator issues a context switch request into a managed firewall with an affected PAN-OS Panorama version, their PAN-OS session cookie is transmitted over cleartext to the firewall. An attacker with the ability to intercept this network traffic between the firewall and Panorama can access the administrator's account and further manipulate devices managed by Panorama.


Remediation

Install updates from vendor's website.

External links