QID 730405
Date Published: 2022-03-24
QID 730405: Palo Alto Networks (PAN-OS) Buffer overflow in authd authentication response Vulnerability (CYR-10833)
PAN OS is the software that runs all Palo Alto Networks next-generation firewalls.
A buffer overflow vulnerability in the authd component of the PAN-OS management server allows authenticated administrators to disrupt system processes and potentially execute arbitrary code with root privileges.
Affected Versions:
PAN-OS 9.0 versions earlier than PAN-OS 9.0.7
PAN-OS 8.1 versions earlier than PAN-OS 8.1.13
PAN-OS 8.0 all versions
PAN-OS 7.1 all versions
QID Detection Logic (Authenticated):
This QID looks for the vulnerable version of PAN-OS
A buffer overflow vulnerability in the authd component of the PAN-OS management server allows authenticated administrators to disrupt system processes and potentially execute arbitrary code with root privileges.
Refer to CYR-10833 for more information about patching this vulnerability.
Workaround:
This issue affects the management interface of PAN-OS and you can mitigate the impact of this issue by following best practices for securing the PAN-OS management interface. Please review the Best Practices for Securing Administrative Access in the PAN-OS technical documentation, available at https://docs.paloaltonetworks.com/best-practices.
- CYR-10833 -
security.paloaltonetworks.com/CVE-2020-2027
CVEs related to QID 730405
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| CYR-10833 |
|