PT-2020-15233 · Palo Alto Networks · Pan-Os Panorama

Ben Nott

·

Published

2020-05-13

·

Updated

2020-05-18

·

CVE-2020-2013

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Palo Alto Networks PAN-OS Panorama versions prior to 7.1.26 Palo Alto Networks PAN-OS Panorama versions prior to 8.1.13 Palo Alto Networks PAN-OS Panorama versions prior to 9.0.6 Palo Alto Networks PAN-OS Panorama versions prior to 9.1.1 Palo Alto Networks PAN-OS Panorama version 8.0
Description A cleartext transmission of sensitive information issue in Palo Alto Networks PAN-OS Panorama discloses an authenticated PAN-OS administrator's PAN-OS session cookie. When an administrator issues a context switch request into a managed firewall with an affected PAN-OS Panorama version, their PAN-OS session cookie is transmitted over cleartext to the firewall. An attacker with the ability to intercept this network traffic between the firewall and Panorama can access the administrator's account and further manipulate devices managed by Panorama.
Recommendations For versions prior to 7.1.26, update to version 7.1.26 or later. For versions prior to 8.1.13, update to version 8.1.13 or later. For versions prior to 9.0.6, update to version 9.0.6 or later. For versions prior to 9.1.1, update to version 9.1.1 or later. For version 8.0, consider upgrading to a later version of PAN-OS.

Fix

Cleartext Transmission of Sensitive Information

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-2013

Affected Products

Pan-Os Panorama