VDB
CVE-2020-2018
CVE-2020-2018
PUBLISHED
CVSS 9 CRITICAL
An authentication bypass vulnerability in Palo Alto Networks PAN-OS Panorama proxy service allows an unauthenticated user with network access to Panorama and the knowledge of the Firewall’s serial number to register the PAN-OS firewall to register the device. After the PAN-OS device is registered, the user can further compromise the PAN-OS instances managed by Panorama. This issue affects: PAN-OS 7.1 versions earlier than 7.1.26; PAN-OS 8.0 versions earlier than 8.0.21; PAN-OS 8.1 versions earlier than 8.1.12; PAN-OS 9.0 versions earlier than 9.0.6.
EPSS 0.32% · 55.3th percentile
Risk Scores
CVSS 3.1
9
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
EPSS Score
0.32%
55.3th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Palo Alto Networks | PAN-OS | 9.0, 8.0.*, 7.1 |
| paloaltonetworks | pan-os | 7.1.0, 8.0.0, 9.0.0 |
Exploit Intelligence
Timeline
- May 13, 2020 CVE Published
- Apr 14, 2021 EPSS Score
- Jun 23, 2021 EPSS Score
- Aug 24, 2021 EPSS Score
- Oct 26, 2021 EPSS Score
- Jan 6, 2022 EPSS Score
- Feb 4, 2022 EPSS Score
- Feb 28, 2022 EPSS Score
- Apr 1, 2022 EPSS Score
- May 1, 2022 EPSS Score
- Jul 3, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
References
- https://security.paloaltonetworks.com/CVE-2020-2018 url
- https://security.paloaltonetworks.com/CVE-2020-1998 advisory
- https://security.paloaltonetworks.com/CVE-2020-2010 advisory
- https://security.paloaltonetworks.com/CVE-2020-1994 advisory
- https://security.paloaltonetworks.com/CVE-2020-2002 advisory
- https://security.paloaltonetworks.com/CVE-2020-2014 advisory
- https://security.paloaltonetworks.com/CVE-2020-1997 advisory
- https://security.paloaltonetworks.com/CVE-2020-2012 advisory
- https://security.paloaltonetworks.com/CVE-2020-2009 advisory
- https://security.paloaltonetworks.com/CVE-2020-1996 advisory
- https://security.paloaltonetworks.com/CVE-2020-2013 advisory
- https://security.paloaltonetworks.com/CVE-2020-2017 advisory
- https://security.paloaltonetworks.com/CVE-2017-7529 advisory
- https://security.paloaltonetworks.com/CVE-2020-2008 advisory
- https://security.paloaltonetworks.com/CVE-2020-2004 advisory
- https://security.paloaltonetworks.com/CVE-2020-2007 advisory
- https://security.paloaltonetworks.com/CVE-2020-1993 advisory
- https://security.paloaltonetworks.com/CVE-2020-2015 advisory
- https://security.paloaltonetworks.com/CVE-2020-2003 advisory
- https://security.paloaltonetworks.com/CVE-2020-2005 advisory
…and 4 more