ZeroHour
Security Affairspublished ()ingested @securityaffairs

Palo Alto Networks fixes a critical flaw in firewall PAN

criticalVulnerabilityimportance 60CVE-2020-2021

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2020-2021
SAML Authentication Bypass in Palo Alto Networks PAN-OS

CVE-2020-2021 is an improper signature-verification flaw (CWE-347) in PAN-OS SAML authentication that lets an unauthenticated network-based attacker bypass identity verification when SAML is enabled and the 'Validate Identity Provider Certificate' option is left unchecked. An attacker with network access to a vulnerable GlobalProtect gateway or portal, GlobalProtect Clientless VPN, Captive Portal, or Prisma Access can gain access to protected resources permitted by the configured authentication and security policies, without affecting session integrity or availability for regular users. If SAML is used to protect the PAN-OS or Panorama web interfaces, the attacker can log in as an administrator and perform administrative actions, making this a worst-case CVSS 10.0 (critical) issue. Affected deployments run PAN-OS 9.1 before 9.1.3, 9.0 before 9.0.9, 8.1 before 8.1.15, or any 8.0 release (end-of-life); PAN-OS 7.1 is not affected, and the flaw cannot be exploited where SAML is unused or certificate validation is enabled. The vendor reported no malicious exploitation at disclosure, but the flaw has since been added to CISA's Known Exploited Vulnerabilities catalog (March 2022) with known ransomware use, and headlines tie it to foreign espionage and APT activity chaining VPN flaws.

Do: Upgrade to PAN-OS 9.1.3, 9.0.9, or 8.1.15 or later as applicable, and migrate off EOL PAN-OS 8.0; PAN-OS 7.1 requires no action. As an immediate mitigation, enable (check) the 'Validate Identity Provider Certificate' option in the SAML Identity Provider Server Profile. Restrict the PAN-OS and Panorama web interfaces to a trusted management network and audit whether SAML is used for GlobalProtect, Captive Portal, Prisma Access, or administrator authentication to confirm exposure.

10.04% KEV ransomware
  • Palo Alto Networks PAN-OS 9.1 versions earlier than 9.1.3; 9.0 versions earlier than 9.0.9; 8.1 versions earlier than 8.1.15; all PAN-OS 8.0 versions (EOL); PAN-OS 7.1 not affected
largetens of thousands of internet-exposed PAN-OS firewalls, gateways and management interfaces, of an installed base of hundreds of thousands
Full article447 words · extracted from securityaffairs.com · click to collapse

Palo Alto Networks addressed a critical flaw in the PAN-OS of its next-generation firewalls that could allow attackers to bypass authentication.

Palo Alto Networks addressed a critical vulnerability, tracked as CVE-2020-2021, in the operating system (PAN‑OS) that powers its next-generation firewalls that could allow unauthenticated network-based attackers to bypass authentication.

“When Security Assertion Markup Language (SAML) authentication is enabled and the ‘Validate Identity Provider Certificate’ option is disabled (unchecked), improper verification of signatures in PAN-OS SAML authentication enables an unauthenticated network-based attacker to access protected resources,” reads the security advisory published by the company. “The attacker must have network access to the vulnerable server to exploit this vulnerability.”

The CVE-2020-2021 vulnerability has been rated as critical severity and received a CVSS 3.x base score of 10.

According to Palo Alto Networks the vulnerability impacts PAN-OS 9.1 versions earlier than PAN-OS 9.1.3; PAN-OS 9.0 versions earlier than PAN-OS 9.0.9; PAN-OS 8.1 versions earlier than PAN-OS 8.1.15, and all versions of PAN-OS 8.0 (EOL). This issue doesn’t affect PAN-OS 7.1.

The company confirmed that the vulnerability cannot be exploited if SAML is not used for authentication and if the ‘Validate Identity Provider Certificate’ option is enabled (checked) in the SAML Identity Provider Server Profile.

“In the case of GlobalProtect Gateways, GlobalProtect Portal, Clientless VPN, Captive Portal, and Prisma Access, an unauthenticated attacker with network access to the affected servers can gain access to protected resources if allowed by configured authentication and Security policies,” Palo Alto Networks explains.

“There is no impact on the integrity and availability of the gateway, portal, or VPN server. An attacker cannot inspect or tamper with sessions of regular users.”

In attacks against PAN-OS and Panorama web interfaces, this vulnerability could be exploited by an unauthenticated attacker with network access to log in as an administrator and perform administrative actions.

The good news is that Palo Alto Networks is not aware of attacks in the wild exploiting this vulnerability.

Admins could determine if their installs are vulnerable following the instructions provided by the company in a knowledge base article.

Customers could inspect the authentication logs, the User-ID logs, ACC Network Activity Source/Destination Regions (Leveraging the Global Filter feature), Custom Reports (Monitor > Report), and GlobalProtect Logs (PAN-OS 9.1.0 and above) to determine if their installs have been compromised.

The presence of unusual usernames or source IP addresses in the logs and reports are indicators of a compromise.

The vulnerability was reported to Palo Alto Networks by Salman Khan from the Cyber Risk and Resilience Team and Cameron Duck from the Identity Services Team at Monash University.

[adrotate banner=”9″][adrotate banner=”12″]

Pierluigi Paganini

(SecurityAffairs – hacking, PAN-OS)

[adrotate banner=”5″]

[adrotate banner=”13″]



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/105351/hacking/critical-flaw-firewall-pan-os.html