PT-2020-2251 · Palo Alto Networks · Pan-Os

Ben Nott

·

Published

2020-05-13

·

Updated

2020-06-23

·

CVE-2020-2018

CVSS v3.1

9.3

Critical

VectorAV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions PAN-OS versions prior to 7.1.26 PAN-OS versions prior to 8.1.12 PAN-OS versions prior to 9.0.6 PAN-OS 8.0 (all versions)
Description The issue is related to an authentication bypass vulnerability in the Panorama context switching feature, which can allow an attacker with network access to a Panorama's management interface to gain privileged access to managed firewalls. The attacker requires some knowledge of managed firewalls to exploit this issue. This issue does not affect Panorama configured with custom certificates authentication for communication between Panorama and managed devices.
Recommendations For PAN-OS versions prior to 7.1.26, update to version 7.1.26 or later. For PAN-OS versions prior to 8.1.12, update to version 8.1.12 or later. For PAN-OS versions prior to 9.0.6, update to version 9.0.6 or later. For PAN-OS 8.0, consider upgrading to a newer version of PAN-OS that is not affected by this issue. As a temporary workaround, consider configuring Panorama with custom certificates authentication for communication between Panorama and managed devices to prevent exploitation.

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2020-02187
CVE-2020-2018

Affected Products

Pan-Os