CVE-2020-1981: PAN-OS: Predictable temporary filename vulnerability allows local privilege escalation
A predictable temporary filename vulnerability in PAN-OS allows local privilege escalation. This issue allows a local attacker who bypassed the restricted shell to execute commands as a low privileged user and gain root access on the PAN-OS hardware or virtual appliance. This issue affects only PAN-OS 8.1 versions earlier than PAN-OS 8.1.13. This issue does not affect PAN-OS 7.1, PAN-OS 9.0, or later PAN-OS versions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
PAN-OSto a version that resolves this vulnerability.Fixed in 8.1.13
Event History
Frequently Asked Questions
What is the severity of CVE-2020-1981?
CVE-2020-1981 is classified with a high severity due to its potential for local privilege escalation.
How do I fix CVE-2020-1981?
To fix CVE-2020-1981, update your PAN-OS to version 8.1.14 or later.
Who is affected by CVE-2020-1981?
CVE-2020-1981 affects local users of PAN-OS versions between 8.1.0 and 8.1.13.
What type of vulnerability is CVE-2020-1981?
CVE-2020-1981 is a predictable temporary filename vulnerability that leads to local privilege escalation.
What can an attacker do with CVE-2020-1981?
An attacker can use CVE-2020-1981 to execute commands as a low privileged user and potentially gain root access on PAN-OS.