CVE-2020-2050 — Improper Authorization in Palo Alto Networks Pan-os
Severity
8.2HIGHNVD
EPSS
0.2%
top 63.12%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedNov 12
Latest updateMay 24
Description
An authentication bypass vulnerability exists in the GlobalProtect SSL VPN component of Palo Alto Networks PAN-OS software that allows an attacker to bypass all client certificate checks with an invalid certificate. A remote attacker can successfully authenticate as any user and gain access to restricted VPN network resources when the gateway or portal is configured to rely entirely on certificate-based authentication. Impacted features that use SSL VPN with client certificate verification are: …
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:NExploitability: 3.9 | Impact: 4.2
Affected Packages3 packages
🔴Vulnerability Details
2GHSA▶
GHSA-cgjw-gjmx-29p4: An authentication bypass vulnerability exists in the GlobalProtect SSL VPN component of Palo Alto Networks PAN-OS software that allows an attacker to↗2022-05-24
CVEList▶
PAN-OS: Authentication bypass vulnerability in GlobalProtect SSL VPN client certificate verification↗2020-11-12
💥Exploits & PoCs
1📋Vendor Advisories
1Palo Alto▶
PAN-OS: Authentication bypass vulnerability in GlobalProtect client certificate verification↗2020-11-11