CVE-2020-1996 MEDIUM

CVE-2020-1996: PAN-OS: Panorama management server log injection

Vendor Palo Alto Networks
Product PAN-OS
Weakness CWE-862 · Missing authorization
Published May 13, 2020
Last update September 17, 2024

CVSS base score

5.3/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality None
Integrity Low

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

What the vulnerability does

01Description

A missing authorization vulnerability in the management server component of PAN-OS Panorama allows a remote unauthenticated user to inject messages into the management server ms.log file. This vulnerability can be leveraged to obfuscate an ongoing attack or fabricate log entries in the ms.log file This issue affects: All versions of PAN-OS 7.1 and 8.0; PAN-OS 8.1 versions earlier than 8.1.14; PAN-OS 9.0 versions earlier than 9.0.9.

Key dates

02Disclosure timeline

May 13, 2020 CVE published
September 17, 2024 Record updated

Related vulnerabilities

04Related CVE