CVE-2020-2028: PAN-OS: OS command injection vulnerability in FIPS-CC mode certificate verification
An OS Command Injection vulnerability in PAN-OS management server allows authenticated administrators to execute arbitrary OS commands with root privileges when uploading a new certificate in FIPS-CC mode. This issue affects: All versions of PAN-OS 7.1 and PAN-OS 8.0; PAN-OS 8.1 versions earlier than PAN-OS 8.1.13; PAN-OS 9.0 versions earlier than PAN-OS 9.0.7.
Affected Software
Remediation
Information
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2020-2028?
CVE-2020-2028 is considered a critical vulnerability due to its potential for remote command execution with elevated privileges.
How do I fix CVE-2020-2028?
To fix CVE-2020-2028, update your PAN-OS to a version later than 7.1.26, 8.0.20, 8.1.13, or 9.0.7.
What systems are affected by CVE-2020-2028?
CVE-2020-2028 affects all versions of PAN-OS from 7.1.0 up to 7.1.26, 8.0.0 up to 8.0.20, and 8.1.0 up to 8.1.13.
What type of vulnerability is CVE-2020-2028?
CVE-2020-2028 is classified as an OS Command Injection vulnerability in the PAN-OS management server.
Who can exploit CVE-2020-2028?
Authenticated administrators can exploit CVE-2020-2028 to execute arbitrary OS commands with root privileges.