Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Maurice Lok-Hin

#29336of 53,633
8.8Total CVSS
Vulnerabilities · 1
PT-2020-15221
8.8
2020-05-13
Palo Alto Networks · Pan-Os · CVE-2020-1998
**Name of the Vulnerable Software and Affected Versions** PAN-OS versions prior to 7.1.26 PAN-OS versions prior to 8.0.21 PAN-OS versions prior to 8.1.13 PAN-OS versions prior to 9.0.6 PAN-OS versions prior to 9.1.1 **Description** An improper authorization issue in PAN-OS mistakenly uses the permissions of local linux users instead of the intended SAML permissions of the account when the username is shared for the purposes of SSO authentication. This can result in authentication bypass and unintended resource access for the user. **Recommendations** For PAN-OS 7.1, update to version 7.1.26 or later. For PAN-OS 8.0, update to version 8.0.21 or later. For PAN-OS 8.1, update to version 8.1.13 or later. For PAN-OS 9.0, update to version 9.0.6 or later. For PAN-OS 9.1, update to version 9.1.1 or later.