PT-2020-15242 · Palo Alto Networks · Pan-Os

Published

2020-05-13

·

Updated

2020-05-15

·

CVE-2020-2016

CVSS v2.0

8.5

High

VectorAV:N/AC:M/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions PAN-OS versions prior to 7.1.26 PAN-OS versions prior to 8.1.13 PAN-OS versions prior to 9.0.6 PAN-OS 8.0 versions
Description A race condition due to insecure creation of a file in a temporary directory allows for root privilege escalation from a limited linux user account. This issue enables an attacker who has escaped the restricted shell as a low privilege administrator to escalate privileges to become root user.
Recommendations For PAN-OS 7.1 versions, update to version 7.1.26 or later. For PAN-OS 8.1 versions, update to version 8.1.13 or later. For PAN-OS 9.0 versions, update to version 9.0.6 or later. For PAN-OS 8.0 versions, there is no information about a newer version that contains a fix for this vulnerability.

Race Condition

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-2016

Affected Products

Pan-Os