CVE-2020-2017: PAN-OS: DOM-Based cross site scripting vulnerability in management web interface
A DOM-Based Cross Site Scripting Vulnerability exists in PAN-OS and Panorama Management Web Interfaces. A remote attacker able to convince an authenticated administrator to click on a crafted link to PAN-OS and Panorama Web Interfaces could execute arbitrary JavaScript code in the administrator's browser and perform administrative actions. This issue affects: PAN-OS 7.1 versions earlier than 7.1.26; PAN-OS 8.1 versions earlier than 8.1.13; PAN-OS 9.0 versions earlier than 9.0.6; All versions of PAN-OS 8.0.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2020-2017?
CVE-2020-2017 is classified as a medium severity vulnerability.
How do I fix CVE-2020-2017?
To fix CVE-2020-2017, you should upgrade to the patched versions of PAN-OS identified by Palo Alto Networks.
Who is affected by CVE-2020-2017?
CVE-2020-2017 affects authenticated administrators using specific versions of PAN-OS and Panorama Management Web Interfaces.
What type of vulnerability is CVE-2020-2017?
CVE-2020-2017 is a DOM-Based Cross Site Scripting vulnerability.
Can CVE-2020-2017 be exploited remotely?
Yes, CVE-2020-2017 can be exploited remotely if an authenticated administrator clicks on a malicious link.