Executive brief
Improper verification of signatures in PAN-OS SAML authentication allows an unauthenticated network-based attacker to bypass authentication and access protected resources or log in as an administrator. This vulnerability exists only when SAML is enabled and the 'Validate Identity Provider Certificate' option is disabled. Affected resources include GlobalProtect Gateway, Portal, Clientless VPN, and the PAN-OS/Panorama web interfaces.
Affected products
- Palo Alto Networks PAN-OS 9.1 versions earlier than 9.1.3; 9.0 versions earlier than 9.0.9; 8.1 versions earlier than 8.1.15; all versions of 8.0 (EOL)
- Palo Alto Networks Prisma Access
Timeline
- 2020-06-29: disclosed: Initial analysis and description provided by vendor.
- 2022-03-25: kev added: Added to CISA's Known Exploited Vulnerabilities Catalog.