PT-2020-15269 · Palo Alto Networks · Pan-Os

Yamata Li

·

Published

2020-09-09

·

Updated

2020-09-15

·

CVE-2020-2044

CVSS v2.0

4.0

Medium

VectorAV:N/AC:L/Au:S/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Palo Alto Networks PAN-OS versions prior to 8.1.16 Palo Alto Networks PAN-OS versions 9.0 prior to 9.0.10 Palo Alto Networks PAN-OS versions 9.1 prior to 9.1.3
Description An information exposure through log file vulnerability may occur where an administrator's password or other sensitive information is logged in cleartext while using the CLI in Palo Alto Networks PAN-OS software. The opcmdhistory.log file, which tracks operational command usage, did not mask all sensitive information. This issue is resolved in PAN-OS 9.1 and later versions, where the opcmdhistory.log file is removed and command usage is recorded in the req stats.log file instead.
Recommendations For PAN-OS 8.1 versions earlier than 8.1.16, update to PAN-OS 8.1.16 or later. For PAN-OS 9.0 versions earlier than 9.0.10, update to PAN-OS 9.0.10 or later. For PAN-OS 9.1 versions earlier than 9.1.3, update to PAN-OS 9.1.3 or later.

Fix

Insertion into Log File

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-2044

Affected Products

Pan-Os