CVE-2020-1991 PUBLISHED CVSS 7.800000190734863 HIGH

An insecure temporary file vulnerability in Palo Alto Networks Traps allows a local authenticated Windows user to escalate privileges or overwrite system files. This issue affects Palo Alto Networks Traps 5.0 versions before 5.0.8; 6.1 versions before 6.1.4 on Windows. This issue does not affect Cortex XDR 7.0. This issue does not affect Traps for Linux or MacOS.

EPSS 0.04% · 10.7th percentile

Risk Scores

CVSS v3.1
7.800000190734863
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Score
0.04%
10.7th percentile

Affected Products

VendorProductVersions
Palo Alto NetworksCortex XDR*
paloaltonetworkstraps5.0, 6.1
Palo Alto NetworksTraps5.0, 6.1

Timeline

References

Open in Interactive Console →