QID 730269
Date Published: 2021-11-25
QID 730269: Palo Alto Networks (PAN-OS) Panorama management server log injection (PAN-117955)
PAN OS is the software that runs all Palo Alto Networks next-generation firewalls.
Affected Version(s):
All versions of PAN-OS 7.1
All versions of PAN-OS 8.0
PAN-OS 8.1 versions earlier than 8.1.14
PAN-OS 9.0 versions earlier than 9.0.9
QID Detection Logic (Authenticated):
This QID looks for the vulnerable version of PAN-OS via XML API.
It allows a remote unauthenticated user to inject messages into the management server ms.log file.
Refer to CVE-2020-1996 for more information about patching this vulnerability.Workaround:
Attacks against this issue can be blocked with signatures for Unique Threat ID 58197 enabled on a different firewall configured to protect the vulnerable management interfaces.
This issue affects the management interface of PAN-OS and is strongly mitigated by following best practices for securing the PAN-OS management interface. Please review the Best Practices for Securing Administrative Access in the PAN-OS technical documentation, available at: https://docs.paloaltonetworks.com.
- PAN-117955 -
security.paloaltonetworks.com/CVE-2020-1996
CVEs related to QID 730269
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| PAN-117955 |
|