An external control of filename vulnerability in the SD WAN component of Palo Alto Networks PAN-OS Panorama allows an authenticated administrator to send a request that results in the creation and write of an arbitrary file on all firewalls managed by the Panorama. In some cases this results in arbitrary code execution with root permissions. This issue affects: All versions of PAN-OS 7.1; PAN-OS 8.1 versions earlier than 8.1.14; PAN-OS 9.0 versions earlier than 9.0.7.
References
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: palo_alto

Published: 2020-05-13T00:00:00

Updated: 2020-05-13T19:07:14

Reserved: 2019-12-04T00:00:00


Link: CVE-2020-2009

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2020-05-13T19:15:13.673

Modified: 2020-05-19T14:10:25.913


Link: CVE-2020-2009

JSON object: View

cve-icon Redhat Information

No data.