CVE-2020-2009

An external control of filename vulnerability in the SD WAN component of Palo Alto Networks PAN-OS Panorama allows an authenticated administrator to send a request that results in the creation and write of an arbitrary file on all firewalls managed by the Panorama. In some cases this results in arbitrary code execution with root permissions. This issue affects: All versions of PAN-OS 7.1; PAN-OS 8.1 versions earlier than 8.1.14; PAN-OS 9.0 versions earlier than 9.0.7.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:paloaltonetworks:pan-os:*:*:*:*:*:*:*:*
cpe:2.3:o:paloaltonetworks:pan-os:*:*:*:*:*:*:*:*
cpe:2.3:o:paloaltonetworks:pan-os:*:*:*:*:*:*:*:*
cpe:2.3:o:paloaltonetworks:pan-os:*:*:*:*:*:*:*:*

History

21 Nov 2024, 05:24

Type Values Removed Values Added
References () https://security.paloaltonetworks.com/CVE-2020-2009 - Vendor Advisory () https://security.paloaltonetworks.com/CVE-2020-2009 - Vendor Advisory

Information

Published : 2020-05-13 19:15

Updated : 2024-11-21 05:24


NVD link : CVE-2020-2009

Mitre link : CVE-2020-2009

CVE.ORG link : CVE-2020-2009


JSON object : View

Products Affected

paloaltonetworks

  • pan-os
CWE
CWE-73

External Control of File Name or Path

CWE-610

Externally Controlled Reference to a Resource in Another Sphere