CVE-2020-2018 PUBLISHED CVSS 9 CRITICAL

An authentication bypass vulnerability in Palo Alto Networks PAN-OS Panorama proxy service allows an unauthenticated user with network access to Panorama and the knowledge of the Firewall’s serial number to register the PAN-OS firewall to register the device. After the PAN-OS device is registered, the user can further compromise the PAN-OS instances managed by Panorama. This issue affects: PAN-OS 7.1 versions earlier than 7.1.26; PAN-OS 8.0 versions earlier than 8.0.21; PAN-OS 8.1 versions earlier than 8.1.12; PAN-OS 9.0 versions earlier than 9.0.6.

EPSS 0.32% · 54.8th percentile

Risk Scores

CVSS v3.1
9
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
EPSS Score
0.32%
54.8th percentile

Affected Products

VendorProductVersions
Palo Alto NetworksPAN-OS8.0.*, 7.1, 8.1
paloaltonetworkspan-os7.1.0, 8.0.0, 8.1.0

Timeline

References

…and 4 more

Open in Interactive Console →