CVE-2020-2006: PAN-OS: Buffer overflow in management server payload parser
A stack-based buffer overflow vulnerability in the management server component of PAN-OS that allows an authenticated user to potentially execute arbitrary code with root privileges. This issue affects: All versions of PAN-OS 7.1 and 8.0; PAN-OS 8.1 versions earlier than 8.1.14.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2020-2006?
CVE-2020-2006 is classified as a critical severity vulnerability with a potential for arbitrary code execution.
How do I fix CVE-2020-2006?
To remediate CVE-2020-2006, upgrade to PAN-OS 8.1.14 or later, or ensure you are running PAN-OS versions 8.0.20 or 7.1.26 or later.
Which versions of PAN-OS are affected by CVE-2020-2006?
CVE-2020-2006 affects all versions of PAN-OS 7.1, 8.0, and versions of PAN-OS 8.1 prior to 8.1.14.
Can CVE-2020-2006 be exploited remotely?
CVE-2020-2006 requires authentication for exploitation, meaning an authenticated user could potentially trigger the vulnerability.
What are the potential impacts of CVE-2020-2006?
Exploitation of CVE-2020-2006 could allow an attacker to execute arbitrary code with root privileges on the affected PAN-OS management server.