Palo Alto Networks Releases Security Updates
Affected platforms
The following platforms are known to be affected:
Palo Alto Networks PAN-OS - 9.1.x prior to 9.1.3, 9.0.x prior to 9.0.9, 8.1.x prior to 8.1.15, and all versions of 8.0.x or 7.1.x
Threat details
Vulnerabilities
Palo Alto Networks has released security updates to address multiple vulnerabilities affecting their PAN-OS firewall operating system. An remote unauthenticated attacker could exploit some or all of these vulnerabilities to take control of an affected system, obtain sensitive information, or cause a denial-of-service condition.
Remediation advice
Users and administrators are encouraged to review the below Palo Alto security advisories and apply any necessary updates.
Remediation steps
| Type | Step |
|---|---|
| Patch |
CVE-2020-2034 PAN-OS: OS command injection vulnerability in GlobalProtect portal https://security.paloaltonetworks.com/CVE-2020-2034 |
|
CVE-2020-2030 PAN-OS: OS command injection vulnerability in the management interface https://security.paloaltonetworks.com/CVE-2020-2030 |
|
| Patch |
CVE-2020-2031 PAN-OS: Integer underflow in the management interface https://security.paloaltonetworks.com/CVE-2020-2031 |
| Patch |
CVE-2020-1982 PAN-OS: TLS 1.0 usage for certain communications with Palo Alto Networks cloud delivered services https://security.paloaltonetworks.com/CVE-2020-1982 |
| Patch |
PAN-SA-2020-0007 Informational: Third-party or open source vulnerabilities that do not impact Palo Alto Networks Products https://security.paloaltonetworks.com/PAN-SA-2020-0007 |
Definitive source of threat updates
CVE Vulnerabilities
Last edited: 9 July 2020 11:29 am