Original Release Date: 9/10/2020
Multiple vulnerabilities have been discovered in Palo Alto PAN-OS, the most severe of which could allow for arbitrary code execution. PAN-OS is an operating system for Palo Alto Network Appliances. An attacker can exploit this issue by sending a malicious request to the Captive Portal or Multi-Factor Authentication interface. Successful exploitation of the most severe of these vulnerabilities could allow an unauthenticated remote attacker to disrupt system processes and potentially execute arbitrary code with root privileges.
There are currently no reports of these vulnerabilities being exploited in the wild.
Government:
Businesses:
Home Users: Low
Multiple vulnerabilities have been discovered in Palo Alto PAN-OS, the most severe of which could allow for arbitrary code execution. Details of the vulnerabilities are as follows:
Successful exploitation of the most severe of these vulnerabilities could allow an unauthenticated remote attacker to gain unauthorized access to the affected application.
We recommend the following actions be taken:
Palo Alto:
https://security.paloaltonetworks.com/
CVE:
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-2040
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-2036
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-2041
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-2037
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-2038
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-2042
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-2039
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-2043
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-2044
We encourage recipients who discover signs of malicious cyber activity to contact us via the cyber incident report form by clicking here.