CVE-2020-2029: PAN-OS: OS command injection vulnerability in management interface certificate generator
An OS Command Injection vulnerability in the PAN-OS web management interface allows authenticated administrators to execute arbitrary OS commands with root privileges by sending a malicious request to generate new certificates for use in the PAN-OS configuration. This issue affects: All versions of PAN-OS 8.0; PAN-OS 7.1 versions earlier than PAN-OS 7.1.26; PAN-OS 8.1 versions earlier than PAN-OS 8.1.13.
Affected Software
Remediation
Information
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2020-2029?
CVE-2020-2029 has a critical severity rating due to its potential for authenticated attackers to execute arbitrary commands with root privileges.
How do I fix CVE-2020-2029?
To fix CVE-2020-2029, update PAN-OS to a version that is not affected, specifically versions above 7.1.26, 8.0.20, and 8.1.13.
Who is affected by CVE-2020-2029?
Authenticated administrators using affected versions of PAN-OS are vulnerable to CVE-2020-2029.
What type of vulnerability is CVE-2020-2029?
CVE-2020-2029 is classified as an OS Command Injection vulnerability.
Can CVE-2020-2029 be exploited remotely?
CVE-2020-2029 requires authenticated access, so it cannot be exploited remotely by unauthenticated users.