CVE-2020-2002Authentication Bypass by Spoofing in Palo Alto Networks Pan-os

Severity
8.1HIGHNVD
EPSS
0.6%
top 30.94%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 13
Latest updateMay 24

Description

An authentication bypass by spoofing vulnerability exists in the authentication daemon and User-ID components of Palo Alto Networks PAN-OS by failing to verify the integrity of the Kerberos key distribution center (KDC) before authenticating users. This affects all forms of authentication that use a Kerberos authentication profile. A man-in-the-middle type of attacker with the ability to intercept communication between PAN-OS and KDC can login to PAN-OS as an administrator. This issue affects: P

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 2.2 | Impact: 5.9

Affected Packages3 packages

NVDpaloaltonetworks/pan-os7.1.07.1.26+3
CVEListV5palo_alto_networks/pan-os8.18.1.13+3
Palo Altopaloalto/pan-os

🔴Vulnerability Details

2
GHSA
GHSA-2vhw-349f-2gq5: An authentication bypass by spoofing vulnerability exists in the authentication daemon and User-ID components of Palo Alto Networks PAN-OS by failing2022-05-24
CVEList
PAN-OS: Spoofed Kerberos key distribution center authentication bypass2020-05-13

💥Exploits & PoCs

1
Exploit-DB
OLK Web Store 2020 - Cross-Site Request Forgery2020-01-24

📋Vendor Advisories

1
Palo Alto
PAN-OS: Spoofed Kerberos key distribution center authentication bypass2020-05-13
CVE-2020-2002 — Authentication Bypass by Spoofing | cvebase