CVE-2020-2016: PAN-OS: Temporary file race condition vulnerability in PAN-OS leads to local privilege escalation
A race condition due to insecure creation of a file in a temporary directory vulnerability in PAN-OS allows for root privilege escalation from a limited linux user account. This allows an attacker who has escaped the restricted shell as a low privilege administrator, possibly by exploiting another vulnerability, to escalate privileges to become root user. This issue affects: PAN-OS 7.1 versions earlier than 7.1.26; PAN-OS 8.1 versions earlier than 8.1.13; PAN-OS 9.0 versions earlier than 9.0.6; All versions of PAN-OS 8.0.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2020-2016?
CVE-2020-2016 has a high severity rating due to its potential for root privilege escalation.
How does CVE-2020-2016 affect PAN-OS?
CVE-2020-2016 allows an attacker to escalate privileges from a low privilege administrator account on PAN-OS.
What versions of PAN-OS are affected by CVE-2020-2016?
CVE-2020-2016 affects PAN-OS versions ranging from 7.1.0 to 7.1.26, 8.0.0 to 8.0.20, 8.1.0 to 8.1.13, and 9.0.0 to 9.0.6.
How do I fix CVE-2020-2016?
To fix CVE-2020-2016, upgrade PAN-OS to a version that is not affected by this vulnerability as recommended by Palo Alto Networks.
Is there a workaround for CVE-2020-2016?
There are no known workarounds for CVE-2020-2016; the recommended solution is to apply the latest software updates.