CVE-2020-2012XML External Entity (XXE) Injection in Palo Alto Networks Pan-os

Severity
7.5HIGHNVD
EPSS
3.5%
top 12.36%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 13
Latest updateMay 24

Description

Improper restriction of XML external entity reference ('XXE') vulnerability in Palo Alto Networks Panorama management service allows remote unauthenticated attackers with network access to the Panorama management interface to read arbitrary files on the system. This issue affects: All versions of PAN-OS for Panorama 7.1 and 8.0; PAN-OS for Panorama 8.1 versions earlier than 8.1.13; PAN-OS for Panorama 9.0 versions earlier than 9.0.7.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 3.9 | Impact: 3.6

Affected Packages3 packages

NVDpaloaltonetworks/pan-os8.1.08.1.13+3
CVEListV5palo_alto_networks/pan-os8.18.1.13+3
Palo Altopaloalto/pan-os

🔴Vulnerability Details

2
GHSA
GHSA-mrg8-5g36-q5f9: Improper restriction of XML external entity reference ('XXE') vulnerability in Palo Alto Networks Panorama management service allows remote unauthenti2022-05-24
CVEList
PAN-OS: Panorama: XML external entity reference ('XXE') vulnerability leads the to information leak2020-05-13

💥Exploits & PoCs

5
Exploit-DB
libupnp 1.6.18 - Stack-based buffer overflow (DoS)2020-11-27
Exploit-DB
CA Unified Infrastructure Management Nimsoft 7.80 - Remote Buffer Overflow2020-03-02
Exploit-DB
Microsoft Windows 10 - Theme API 'ThemePack' File Parsing2020-01-29
Exploit-DB
HP Operations Agent - Opcode 'coda.exe' 0x8c Buffer Overflow (Metasploit)2012-10-29
Nuclei
Canon Devices - Authentication Bypass in Catwalk Server

📋Vendor Advisories

1
Palo Alto
PAN-OS: Panorama: XML external entity reference ('XXE') vulnerability leads the to information leak2020-05-13

🕵️Threat Intelligence

1
Unit42
Threat Brief: Microsoft DNS Server Wormable Vulnerability CVE-2020-13502020-07-21
CVE-2020-2012 — XML External Entity (XXE) Injection | cvebase