PT-2020-15221 · Palo Alto Networks · Pan-Os
Maurice Lok-Hin
·
Published
2020-05-13
·
Updated
2020-05-19
·
CVE-2020-1998
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
PAN-OS versions prior to 7.1.26
PAN-OS versions prior to 8.0.21
PAN-OS versions prior to 8.1.13
PAN-OS versions prior to 9.0.6
PAN-OS versions prior to 9.1.1
Description
An improper authorization issue in PAN-OS mistakenly uses the permissions of local linux users instead of the intended SAML permissions of the account when the username is shared for the purposes of SSO authentication. This can result in authentication bypass and unintended resource access for the user.
Recommendations
For PAN-OS 7.1, update to version 7.1.26 or later.
For PAN-OS 8.0, update to version 8.0.21 or later.
For PAN-OS 8.1, update to version 8.1.13 or later.
For PAN-OS 9.0, update to version 9.0.6 or later.
For PAN-OS 9.1, update to version 9.1.1 or later.
Fix
Incorrect Authorization
Improper Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Pan-Os