CVE-2020-2000: PAN-OS: OS command injection and memory corruption vulnerability
An OS command injection and memory corruption vulnerability in the PAN-OS management web interface that allows authenticated administrators to disrupt system processes and potentially execute arbitrary code and OS commands with root privileges. This issue impacts: PAN-OS 8.1 versions earlier than PAN-OS 8.1.16; PAN-OS 9.0 versions earlier than PAN-OS 9.0.10; PAN-OS 9.1 versions earlier than PAN-OS 9.1.4; PAN-OS 10.0 versions earlier than PAN-OS 10.0.1.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2020-2000?
CVE-2020-2000 is an OS command injection and memory corruption vulnerability in the PAN-OS management web interface.
Who is affected by CVE-2020-2000?
PAN-OS 8.1 versions earlier than 8.1.16, PAN-OS 9.0 versions earlier than 9.0.10, PAN-OS 9.1 versions earlier than 9.1.4, and PAN-OS 10.0 versions earlier than 10.0.1 are affected.
What is the severity of CVE-2020-2000?
CVE-2020-2000 has a severity rating of 7.2 (critical).
How can I fix CVE-2020-2000?
Apply the necessary security patches provided by Palo Alto Networks to upgrade PAN-OS to versions 8.1.16, 9.0.10, 9.1.4, or 10.0.1.
Where can I find more information about CVE-2020-2000?
You can find more information about CVE-2020-2000 on the Palo Alto Networks security advisory page: [https://security.paloaltonetworks.com/CVE-2020-2000](https://security.paloaltonetworks.com/CVE-2020-2000)