ZeroHour
Security Affairspublished ()ingested @securityaffairs

Palo Alto Networks fixes another high severity issue in PAN

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2020-2021
SAML Authentication Bypass in Palo Alto Networks PAN-OS

CVE-2020-2021 is an improper signature-verification flaw (CWE-347) in PAN-OS SAML authentication that lets an unauthenticated network-based attacker bypass identity verification when SAML is enabled and the 'Validate Identity Provider Certificate' option is left unchecked. An attacker with network access to a vulnerable GlobalProtect gateway or portal, GlobalProtect Clientless VPN, Captive Portal, or Prisma Access can gain access to protected resources permitted by the configured authentication and security policies, without affecting session integrity or availability for regular users. If SAML is used to protect the PAN-OS or Panorama web interfaces, the attacker can log in as an administrator and perform administrative actions, making this a worst-case CVSS 10.0 (critical) issue. Affected deployments run PAN-OS 9.1 before 9.1.3, 9.0 before 9.0.9, 8.1 before 8.1.15, or any 8.0 release (end-of-life); PAN-OS 7.1 is not affected, and the flaw cannot be exploited where SAML is unused or certificate validation is enabled. The vendor reported no malicious exploitation at disclosure, but the flaw has since been added to CISA's Known Exploited Vulnerabilities catalog (March 2022) with known ransomware use, and headlines tie it to foreign espionage and APT activity chaining VPN flaws.

Do: Upgrade to PAN-OS 9.1.3, 9.0.9, or 8.1.15 or later as applicable, and migrate off EOL PAN-OS 8.0; PAN-OS 7.1 requires no action. As an immediate mitigation, enable (check) the 'Validate Identity Provider Certificate' option in the SAML Identity Provider Server Profile. Restrict the PAN-OS and Panorama web interfaces to a trusted management network and audit whether SAML is used for GlobalProtect, Captive Portal, Prisma Access, or administrator authentication to confirm exposure.

10.04% KEV ransomware
  • Palo Alto Networks PAN-OS 9.1 versions earlier than 9.1.3; 9.0 versions earlier than 9.0.9; 8.1 versions earlier than 8.1.15; all PAN-OS 8.0 versions (EOL); PAN-OS 7.1 not affected
largetens of thousands of internet-exposed PAN-OS firewalls, gateways and management interfaces, of an installed base of hundreds of thousands
CVE-2020-2034
An OS Command Injection vulnerability in the PAN-OS GlobalProtect portal allows an unauthenticated network based attacker to execute arbitrary OS commands with

An OS Command Injection vulnerability in the PAN-OS GlobalProtect portal allows an unauthenticated network based attacker to execute arbitrary OS commands with root privileges. An attacker requires some knowledge of the firewall to exploit this issue. This issue can not be exploited if GlobalProtect portal feature is not enabled. This issue impacts PAN-OS 9.1 versions earlier than PAN-OS 9.1.3; PAN-OS 8.1 versions earlier than PAN-OS 8.1.15; PAN-OS 9.0 versions earlier than PAN-OS 9.0.9; all versions of PAN-OS 8.0 and PAN-OS 7.1. Prisma Access services are not impacted by this vulnerability.

NVD description · AI analysis pending
8.17%
  • paloaltonetworks pan-os
Full article334 words · extracted from securityaffairs.com · click to collapse

Palo Alto Networks addressed a new severe vulnerability in the PAN-OS GlobalProtect portal that impacts PAN next-generation firewalls.

Recently Palo Alto Network addressed a critical vulnerability, tracked as CVE-2020-2021, affecting the PAN-OS operating system that powers its next-generation firewall. The flaw could allow unauthenticated network-based attackers to bypass authentication, it has been rated as critical severity and received a CVSS 3.x base score of 10.

Now the security firm addressed an OS command injection vulnerability tracked as CVE-2020-2034 that could allow unauthenticated remote attackers to execute arbitrary OS commands with root privileges on vulnerable devices.

The CVE-2020-2034 flaw can be exploited by attackers with network access to vulnerable servers, it has been rated as high severity and received a CVSS 3.x base score of 8.1.

Experts pointed out that the flaw doesn’t require user interaction to be exploited.

“An OS Command Injection vulnerability in the PAN-OS GlobalProtect portal allows an unauthenticated network-based attacker to execute arbitrary OS commands with root privileges.” reads the advisory published by Palo Alto Networks. “An attacker would require some level of specific information about the configuration of an impacted firewall or perform brute-force attacks to exploit this issue. This issue cannot be exploited if the GlobalProtect portal feature is not enabled.”

At the time it is not clear what information of the firewall are needed to the attackers to exploit the flaw.

The vulnerability can not be exploited only if GlobalProtect portal feature is enabled, Prisma Access services are not impacted by this vulnerability.

This vulnerability affects PAN-OS 9.1 versions earlier than PAN-OS 9.1.3; PAN-OS 8.1 versions earlier than PAN-OS 8.1.15; PAN-OS 9.0 versions earlier than PAN-OS 9.0.9; all versions of PAN-OS 8.0 and PAN-OS 7.1.

The vulnerability was discovered by Yamata Li of Palo Alto Networks Threat Research Team as part of an internal security review.

Palo Alto Networks is not aware of attacks in the wild attempting to exploit this vulnerability.

[adrotate banner=”9″][adrotate banner=”12″]

Pierluigi Paganini

(SecurityAffairs – hacking, PAN-OS)

[adrotate banner=”5″]

[adrotate banner=”13″]



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/105693/hacking/palo-alto-networks-pan-os-flaw.html