CVE-2020-1993: PAN-OS: GlobalProtect Portal PHP session fixation vulnerability
The GlobalProtect Portal feature in PAN-OS does not set a new session identifier after a successful user login, which allows session fixation attacks, if an attacker is able to control a user's session ID. This issue affects: All PAN-OS 7.1 and 8.0 versions; PAN-OS 8.1 versions earlier than 8.1.14; PAN-OS 9.0 versions earlier than 9.0.8.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2020-1993?
CVE-2020-1993 is considered a high severity vulnerability due to the potential for session fixation attacks.
How do I fix CVE-2020-1993?
To resolve CVE-2020-1993, upgrade to a patched version of PAN-OS beyond the affected versions listed.
What impact does CVE-2020-1993 have on user sessions?
CVE-2020-1993 allows attackers to control a user's session ID, leading to unauthorized access to user sessions.
Which versions of PAN-OS are affected by CVE-2020-1993?
CVE-2020-1993 affects all PAN-OS versions from 7.1.x, 8.0.x, and specific versions of 8.1.x up to 8.1.13.
Is a workaround available for CVE-2020-1993?
No official workaround is provided for CVE-2020-1993; the best mitigation is to update to the latest version of PAN-OS.