CVE-2020-2011: PAN-OS: Panorama registration denial of service
An improper input validation vulnerability in the configuration daemon of Palo Alto Networks PAN-OS Panorama allows for a remote unauthenticated user to send a specifically crafted registration request to the device that causes the configuration service to crash. Repeated attempts to send this request result in denial of service to all PAN-OS Panorama services by restarting the device and putting it into maintenance mode. This issue affects: All versions of PAN-OS 7.1, PAN-OS 8.0; PAN-OS 8.1 versions earlier than 8.1.14; PAN-OS 9.0 versions earlier than 9.0.7; PAN-OS 9.1 versions earlier than 9.1.0.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2020-2011?
CVE-2020-2011 is rated as high severity due to its potential to allow remote unauthenticated users to crash the configuration service.
How do I fix CVE-2020-2011?
To fix CVE-2020-2011, you should upgrade your Palo Alto Networks PAN-OS to a version above 7.1.26, 8.0.20, or 8.1.14, and ensure you are on 9.1.0 or later.
Which versions of PAN-OS are affected by CVE-2020-2011?
CVE-2020-2011 affects Palo Alto Networks PAN-OS versions 7.1.0 to 7.1.26, 8.0.0 to 8.0.20, 8.1.0 to 8.1.14, and 9.0.0 to 9.1.0.
Is CVE-2020-2011 exploitable remotely?
Yes, CVE-2020-2011 is exploitable remotely by unauthenticated users through specially crafted registration requests.
What are the consequences of exploiting CVE-2020-2011?
Exploiting CVE-2020-2011 can cause the configuration service of PAN-OS Panorama to crash, resulting in potential denial-of-service impacts.