CVE-2020-2030: PAN-OS: OS command injection vulnerability in the management interface
An OS Command Injection vulnerability in the PAN-OS management interface that allows authenticated administrators to execute arbitrary OS commands with root privileges. This issue impacts PAN-OS 8.1 versions earlier than PAN-OS 8.1.15; and all versions of PAN-OS 7.1 and PAN-OS 8.0. This issue does not impact PAN-OS 9.0, PAN-OS 9.1, or Prisma Access services.
Affected Software
Remediation
Information
Information
Event History
Frequently Asked Questions
What is CVE-2020-2030?
CVE-2020-2030 is an OS Command Injection vulnerability in the PAN-OS management interface that allows authenticated administrators to execute arbitrary OS commands with root privileges.
How severe is CVE-2020-2030?
CVE-2020-2030 has a severity rating of 7.2 (critical).
Which versions of PAN-OS are affected by CVE-2020-2030?
CVE-2020-2030 impacts PAN-OS 8.1 versions earlier than PAN-OS 8.1.15, and all versions of PAN-OS 7.1 and PAN-OS 8.0.
How can I fix CVE-2020-2030?
To fix CVE-2020-2030, update PAN-OS to version 8.1.15 for PAN-OS 8.1, version 7.1.26 for PAN-OS 7.1, and version 8.0.20 for PAN-OS 8.0.
Where can I find more information about CVE-2020-2030?
More information about CVE-2020-2030 can be found at the following reference: https://security.paloaltonetworks.com/CVE-2020-2030