
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2020-2021 is a critical authentication bypass vulnerability in Palo Alto Networks' PAN-OS SAML authentication system. The vulnerability was disclosed on June 29, 2020, affecting PAN-OS versions 9.1 (earlier than 9.1.3), 9.0 (earlier than 9.0.9), 8.1 (earlier than 8.1.15), and all versions of PAN-OS 8.0. When Security Assertion Markup Language (SAML) authentication is enabled and the 'Validate Identity Provider Certificate' option is disabled, the system fails to properly verify SAML signatures, allowing unauthorized access to protected resources (Palo Alto).
The vulnerability received a CVSS Base Score of 10.0 (Critical) with the vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H. The issue stems from improper verification of signatures in PAN-OS SAML authentication when the 'Validate Identity Provider Certificate' option is disabled. Resources that can be protected by SAML-based single sign-on authentication include GlobalProtect Gateway, GlobalProtect Portal, GlobalProtect Clientless VPN, Authentication and Captive Portal, PAN-OS next-generation firewalls (PA-Series, VM-Series), Panorama web interfaces, and Prisma Access (Palo Alto).
The vulnerability allows an unauthenticated attacker with network access to the affected servers to gain access to protected resources if allowed by configured authentication and Security policies. In the case of PAN-OS and Panorama web interfaces, attackers can log in as administrators and perform administrative actions. For GlobalProtect Gateways, Portal, Clientless VPN, Captive Portal, and Prisma Access, attackers can gain unauthorized access to protected resources (Palo Alto).
The vulnerability requires network access to the vulnerable server for exploitation. The attacker must target systems where SAML authentication is enabled and the 'Validate Identity Provider Certificate' option is disabled. As of the initial disclosure, Palo Alto Networks was not aware of any malicious attempts to exploit this vulnerability in the wild (Palo Alto, TrustedSec).
Organizations can mitigate this vulnerability by either upgrading to fixed versions (PAN-OS 8.1.15, PAN-OS 9.0.9, PAN-OS 9.1.3, or later versions) or by ensuring that the 'Validate Identity Provider Certificate' option is enabled in the SAML Identity Provider Server Profile. Using a different authentication method and disabling SAML authentication will completely mitigate the issue. For organizations using Prisma Access services, all services have been upgraded to resolve this issue and are no longer vulnerable (Palo Alto).
US Cyber Command urged timely patching based on the severity of this exposure. The vulnerability received significant attention from the cybersecurity community, with researchers noting that this configuration issue might be indicative of a systemic problem in SAML implementations. Many popular Identity Providers, including Microsoft's Azure Active Directory and Okta, had documentation suggesting the disabling of certificate validation, which contributed to the widespread potential impact (TrustedSec).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."