PT-2020-5818 · Palo Alto Networks · Globalprotect Gateway+4

Nicholas Newsom

·

Published

2020-11-11

·

Updated

2020-11-24

·

CVE-2020-2050

CVSS v2.0

8.5

High

VectorAV:N/AC:L/Au:N/C:C/I:P/A:N
Name of the Vulnerable Software and Affected Versions: PAN-OS versions prior to 8.1.17 PAN-OS versions prior to 9.0.11 PAN-OS versions prior to 9.1.5 PAN-OS versions prior to 10.0.1
Description: An authentication bypass issue exists in the GlobalProtect SSL VPN component of Palo Alto Networks PAN-OS software, allowing an attacker to bypass all client certificate checks with an invalid certificate. A remote attacker can successfully authenticate as any user and gain access to restricted VPN network resources when the gateway or portal is configured to rely entirely on certificate-based authentication. Impacted features include GlobalProtect Gateway, GlobalProtect Portal, and GlobalProtect Clientless VPN. In configurations where client certificate verification is used with other authentication methods, the protections added by the certificate check are ignored.
Recommendations: For PAN-OS versions prior to 8.1.17, update to version 8.1.17 or later. For PAN-OS versions prior to 9.0.11, update to version 9.0.11 or later. For PAN-OS versions prior to 9.1.5, update to version 9.1.5 or later. For PAN-OS versions prior to 10.0.1, update to version 10.0.1 or later. As a temporary workaround, consider restricting access to the GlobalProtect SSL VPN component until a patch is available.

Fix

Improper Authentication

Improper Certificate Validation

Improper Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-01787
CVE-2020-2050

Affected Products

Globalprotect Clientless Vpn
Globalprotect Gateway
Globalprotect Portal
Globalprotect Ssl Vpn
Pan-Os