CVE-2020-1996: PAN-OS: Panorama management server log injection
A missing authorization vulnerability in the management server component of PAN-OS Panorama allows a remote unauthenticated user to inject messages into the management server ms.log file. This vulnerability can be leveraged to obfuscate an ongoing attack or fabricate log entries in the ms.log file This issue affects: All versions of PAN-OS 7.1 and 8.0; PAN-OS 8.1 versions earlier than 8.1.14; PAN-OS 9.0 versions earlier than 9.0.9.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2020-1996?
CVE-2020-1996 has a severity rating of high due to the potential for unauthorized access and log tampering.
How do I fix CVE-2020-1996?
To fix CVE-2020-1996, upgrade to PAN-OS versions 8.0.21, 8.1.14, 9.0.9, or later, as these versions include the necessary security patch.
What types of attacks can CVE-2020-1996 facilitate?
CVE-2020-1996 can facilitate attacks that involve log injection, allowing attackers to obfuscate their activities or fabricate log entries.
Which versions of PAN-OS are affected by CVE-2020-1996?
CVE-2020-1996 affects PAN-OS versions from 7.1.0 to 7.1.26, 8.0.0 to 8.0.20, 8.1.0 to 8.1.13, and 9.0.0 to 9.0.8.
Who is vulnerable to CVE-2020-1996?
Organizations using affected versions of Palo Alto Networks PAN-OS are vulnerable to CVE-2020-1996 if the management server is not properly secured.