
Cloud Vulnerability DB
A community-led vulnerabilities database
An OS Command Injection vulnerability (CVE-2020-2034) was discovered in the PAN-OS GlobalProtect portal, allowing unauthenticated network-based attackers to execute arbitrary OS commands with root privileges. The vulnerability was discovered by Yamata Li of Palo Alto Networks during an internal security review and disclosed on July 8, 2020. The issue affects PAN-OS versions 9.1 (earlier than 9.1.3), 8.1 (earlier than 8.1.15), 9.0 (earlier than 9.0.9), and all versions of PAN-OS 8.0 and 7.1. Prisma Access services are not impacted by this vulnerability (Palo Advisory).
The vulnerability has been assigned a CVSS 3.1 base score of 8.1 (HIGH), with the following vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H. The attack vector is network-based, requiring high complexity but no privileges or user interaction. The vulnerability can only be exploited when the GlobalProtect portal feature is enabled (Palo Advisory, NVD).
Successful exploitation of this vulnerability allows attackers to execute arbitrary OS commands with root privileges on affected devices. This could potentially lead to complete system compromise, affecting the confidentiality, integrity, and availability of the device (Palo Advisory).
The vulnerability requires specific information about the configuration of an impacted firewall or requires performing brute-force attacks to exploit successfully. According to security researchers, this implies that attacks would need to be customized per device and are not easily wormable. Palo Alto Networks stated they were not aware of any malicious attempts to exploit this vulnerability in the wild (Bleeping Computer).
The vulnerability has been fixed in PAN-OS versions 8.1.15, 9.0.9, 9.1.3, and all later versions. For systems that cannot be immediately updated, Palo Alto Networks recommends enabling signatures for Unique Threat ID 58658 on traffic destined for the GlobalProtect portal to block potential attacks. PAN-OS 7.1 and PAN-OS 8.0 are end-of-life and will not receive security updates to address this vulnerability (Palo Advisory).
The vulnerability received significant attention following the disclosure of CVE-2020-2021, another critical vulnerability in PAN-OS. Security researchers noted that this increased scrutiny could lead to higher likelihood of exploitation by both APT and commodity threat actors (Bleeping Computer).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."