CVE-2020-1980: PAN-OS: Shell injection vulnerability in PAN-OS CLI allows execution of shell commands
A shell command injection vulnerability in the PAN-OS CLI allows a local authenticated user to escape the restricted shell and escalate privileges. This issue affects only PAN-OS 8.1 versions earlier than PAN-OS 8.1.13. This issue does not affect PAN-OS 7.1, PAN-OS 9.0, or later PAN-OS versions. This issue is fixed in PAN-OS 8.1.13, and all later versions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
PAN-OS (PAN-OS CLI)to a version that resolves this vulnerability.Fixed in 8.1.13
Event History
Frequently Asked Questions
What is the severity of CVE-2020-1980?
CVE-2020-1980 is classified as a high severity vulnerability due to its potential for privilege escalation.
How do I fix CVE-2020-1980?
To mitigate CVE-2020-1980, upgrade your PAN-OS to version 8.1.13 or later.
Who is affected by CVE-2020-1980?
CVE-2020-1980 affects local authenticated users on PAN-OS 8.1 versions prior to 8.1.13.
What impact does CVE-2020-1980 have?
CVE-2020-1980 allows a local authenticated user to escape the restricted shell and escalate their privileges.
Is CVE-2020-1980 present in PAN-OS versions 7.1 or 9.0?
No, CVE-2020-1980 does not affect PAN-OS 7.1 or PAN-OS 9.0 and later versions.