#VU27897 Arbitrary file upload in Palo Alto PAN-OS - CVE-2020-2001
Published: May 14, 2020
Palo Alto PAN-OS
Palo Alto Networks, Inc.
Description
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to insufficient validation of file during file upload in the Palo Alto Networks PAN-OS Panorama XSLT processing logic. A remote non-authenticated attacker can upload a malicious file and execute it on the system with administrator privileges.