CVE-2020-2003

CVE-2020-2003

An external control of filename vulnerability in the command processing of PAN-OS allows an authenticated administrator to delete arbitrary system files affecting the integrity of the system or causing denial of service to all PAN-OS services.

This issue affects:
All versions of PAN-OS 7.1;
PAN-OS 8.1 versions before 8.1.14;
PAN-OS 9.0 versions before 9.0.7;
PAN-OS 9.1 versions before 9.1.1.

Source: CVE-2020-2003

CVE-2020-2009

CVE-2020-2009

An external control of filename vulnerability in the SD WAN component of Palo Alto Networks PAN-OS Panorama allows an authenticated administrator to send a request that results in the creation and write of an arbitrary file on all firewalls managed by the Panorama. In some cases this results in arbitrary code execution with root permissions.
This issue affects:

All versions of PAN-OS 7.1;

PAN-OS 8.1 versions earlier than 8.1.14;

PAN-OS 9.0 versions earlier than 9.0.7.

Source: CVE-2020-2009

CVE-2020-1993

CVE-2020-1993

The GlobalProtect Portal feature in PAN-OS does not set a new session identifier after a successful user login, which allows session fixation attacks, if an attacker is able to control a user’s session ID.
This issue affects:
All PAN-OS 7.1 and 8.0 versions;
PAN-OS 8.1 versions earlier than 8.1.14;
PAN-OS 9.0 versions earlier than 9.0.8.

Source: CVE-2020-1993

CVE-2020-2002

CVE-2020-2002

An authentication bypass by spoofing vulnerability exists in the authentication daemon and User-ID components of Palo Alto Networks PAN-OS by failing to verify the integrity of the Kerberos key distribution center (KDC) before authenticating users. This affects all forms of authentication that use a Kerberos authentication profile. A man-in-the-middle type of attacker with the ability to intercept communication between PAN-OS and KDC can login to PAN-OS as an administrator.
This issue affects:
PAN-OS 7.1 versions earlier than 7.1.26;
PAN-OS 8.0 versions earlier than 8.0.21;
PAN-OS 8.1 versions earlier than 8.1.13;
PAN-OS 9.0 versions earlier than 9.0.6.

Source: CVE-2020-2002

CVE-2020-1995

CVE-2020-1995

A NULL pointer dereference vulnerability in Palo Alto Networks PAN-OS allows an authenticated administrator to send a request that causes the rasmgr daemon to crash. Repeated attempts to send this request result in denial of service to all PAN-OS services by restarting the device and putting it into maintenance mode.
This issue affects:

PAN-OS 9.1 versions earlier than 9.1.2.

Source: CVE-2020-1995

CVE-2020-1996

CVE-2020-1996

A missing authorization vulnerability in the management server component of PAN-OS Panorama allows a remote unauthenticated user to inject messages into the management server ms.log file. This vulnerability can be leveraged to obfuscate an ongoing attack or fabricate log entries in the ms.log file
This issue affects:

All versions of PAN-OS 7.1 and 8.0;

PAN-OS 8.1 versions earlier than 8.1.14;

PAN-OS 9.0 versions earlier than 9.0.9.

Source: CVE-2020-1996

CVE-2020-1997

CVE-2020-1997

An open redirection vulnerability in the GlobalProtect component of Palo Alto Networks PAN-OS allows an attacker to specify an arbitrary redirection target away from the trusted GlobalProtect gateway. If the user then successfully authenticates it will cause them to access an unexpected and potentially malicious website.
This issue affects:

PAN-OS 7.1 versions earlier than 7.1.26;

PAN-OS 8.0 versions earlier than 8.0.14.

Source: CVE-2020-1997

CVE-2020-1998

CVE-2020-1998

An improper authorization vulnerability in PAN-OS that mistakenly uses the permissions of local linux users instead of the intended SAML permissions of the account when the username is shared for the purposes of SSO authentication. This can result in authentication bypass and unintended resource access for the user.
This issue affects:

PAN-OS 7.1 versions earlier than 7.1.26;

PAN-OS 8.0 versions earlier than 8.0.21;

PAN-OS 8.1 versions earlier than 8.1.13;

PAN-OS 9.0 versions earlier than 9.0.6;

PAN-OS 9.1 versions earlier than 9.1.1.

Source: CVE-2020-1998

CVE-2020-1994

CVE-2020-1994

A predictable temporary file vulnerability in PAN-OS allows a local authenticated user with shell access to corrupt arbitrary system files affecting the integrity of the system.

This issue affects:
All versions of PAN-OS 7.1 and 8.0;
PAN-OS 8.1 versions earlier than 8.1.13;
PAN-OS 9.0 versions earlier than 9.0.7.

Source: CVE-2020-1994