PT-2020-15233 · Palo Alto Networks · Pan-Os Panorama
Ben Nott
·
Published
2020-05-13
·
Updated
2020-05-18
·
CVE-2020-2013
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Palo Alto Networks PAN-OS Panorama versions prior to 7.1.26
Palo Alto Networks PAN-OS Panorama versions prior to 8.1.13
Palo Alto Networks PAN-OS Panorama versions prior to 9.0.6
Palo Alto Networks PAN-OS Panorama versions prior to 9.1.1
Palo Alto Networks PAN-OS Panorama version 8.0
Description
A cleartext transmission of sensitive information issue in Palo Alto Networks PAN-OS Panorama discloses an authenticated PAN-OS administrator's PAN-OS session cookie. When an administrator issues a context switch request into a managed firewall with an affected PAN-OS Panorama version, their PAN-OS session cookie is transmitted over cleartext to the firewall. An attacker with the ability to intercept this network traffic between the firewall and Panorama can access the administrator's account and further manipulate devices managed by Panorama.
Recommendations
For versions prior to 7.1.26, update to version 7.1.26 or later.
For versions prior to 8.1.13, update to version 8.1.13 or later.
For versions prior to 9.0.6, update to version 9.0.6 or later.
For versions prior to 9.1.1, update to version 9.1.1 or later.
For version 8.0, consider upgrading to a later version of PAN-OS.
Fix
Cleartext Transmission of Sensitive Information
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Pan-Os Panorama