CVE-2020-2009: PAN-OS: Panorama SD WAN arbitrary file creation
An external control of filename vulnerability in the SD WAN component of Palo Alto Networks PAN-OS Panorama allows an authenticated administrator to send a request that results in the creation and write of an arbitrary file on all firewalls managed by the Panorama. In some cases this results in arbitrary code execution with root permissions. This issue affects: All versions of PAN-OS 7.1; PAN-OS 8.1 versions earlier than 8.1.14; PAN-OS 9.0 versions earlier than 9.0.7.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2020-2009?
CVE-2020-2009 is rated as a critical vulnerability due to its potential for an authenticated attacker to create arbitrary files.
How do I fix CVE-2020-2009?
To fix CVE-2020-2009, upgrade your Palo Alto Networks PAN-OS to a version that is not affected by this vulnerability.
Which versions are affected by CVE-2020-2009?
CVE-2020-2009 affects Palo Alto Networks PAN-OS versions 7.1.0 to 7.1.26, 8.0.0 to 8.0.20, 8.1.0 to 8.1.13, and 9.0.0 to 9.0.6.
Who is impacted by CVE-2020-2009?
Authenticated administrators using vulnerable versions of Palo Alto Networks PAN-OS Panorama are impacted by CVE-2020-2009.
What is an external control of filename vulnerability in CVE-2020-2009?
The external control of filename vulnerability in CVE-2020-2009 allows an attacker to write arbitrary files on all firewalls managed by Panorama.