Junglewise Threat Intelligence

CVE-2020-2021: Palo Alto Networks PAN-OS Authentication Bypass Vulnerability

CVE-2020-2021 · Severity: critical · CVSS 10 · Exploited in the wild · Published 2022-03-25

Technologies: Palo Alto Networks Prisma Access, Palo Alto Networks PAN-OS. Vendors: Palo Alto Networks, Palo Alto Networks.

Executive brief

Improper verification of signatures in PAN-OS SAML authentication allows an unauthenticated network-based attacker to bypass authentication and access protected resources or log in as an administrator. This vulnerability exists only when SAML is enabled and the 'Validate Identity Provider Certificate' option is disabled. Affected resources include GlobalProtect Gateway, Portal, Clientless VPN, and the PAN-OS/Panorama web interfaces.

Affected products

  • Palo Alto Networks PAN-OS 9.1 versions earlier than 9.1.3; 9.0 versions earlier than 9.0.9; 8.1 versions earlier than 8.1.15; all versions of 8.0 (EOL)
  • Palo Alto Networks Prisma Access

Timeline

  • 2020-06-29: disclosed: Initial analysis and description provided by vendor.
  • 2022-03-25: kev added: Added to CISA's Known Exploited Vulnerabilities Catalog.

Related threats