cbcvebase.
CVE-2020-2013
published 2020-05-13

CVE-2020-2013: A cleartext transmission of sensitive information vulnerability in Palo Alto Networks PAN-OS Panorama that discloses an authenticated PAN-OS administrator's…

PriorityP341high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
0.64%
46.0th percentile
A cleartext transmission of sensitive information vulnerability in Palo Alto Networks PAN-OS Panorama that discloses an authenticated PAN-OS administrator's PAN-OS session cookie. When an administrator issues a context switch request into a managed firewall with an affected PAN-OS Panorama version, their PAN-OS session cookie is transmitted over cleartext to the firewall. An attacker with the ability to intercept this network traffic between the firewall and Panorama can access the administrator's account and further manipulate devices managed by Panorama. This issue affects: PAN-OS 7.1 versions earlier than 7.1.26; PAN-OS 8.1 versions earlier than 8.1.13; PAN-OS 9.0 versions earlier than 9.0.6; PAN-OS 9.1 versions earlier than 9.1.1; All version of PAN-OS 8.0;

Affected

12 ranges
VendorProductVersion rangeFixed in
joyentjson>= 0 < 2.3.02.3.0
palo_alto_networkspan-os
palo_alto_networkspan-os>= 7.1 < 7.1.267.1.26
palo_alto_networkspan-os>= 8.1 < 8.1.138.1.13
palo_alto_networkspan-os>= 9.0 < 9.0.69.0.6
palo_alto_networkspan-os>= 9.1 < 9.1.19.1.1
paloaltopan-os
paloaltonetworkspan-os7.1.0 – 7.1.26
paloaltonetworkspan-os8.0.0 – 8.0.20
paloaltonetworkspan-os>= 8.1.0 < 8.1.138.1.13
paloaltonetworkspan-os>= 9.0.0 < 9.0.69.0.6
paloaltonetworkspan-os>= 9.1.0 < 9.1.19.1.1

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
ghsa7.5HIGH
vendor_redhat6.8MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.