Palo Alto Networks PAN-OS是美国Palo Alto Networks公司的一套为其防火墙设备开发的操作系统。 Palo Alto Networks PAN-OS 存在命令操作系统命令注入漏洞。该漏洞源于外部输入数据构造可执行命令过程中,网络系统或产品未正确过滤其中的特殊元素。攻击者可利用该漏洞执行非法命令。攻击者可利用该漏洞执行任意操作系统命令。以下是受影响的产品及版本:9.0.10到9.0版本、9.1.4到9.1版本、10.0到10.0.1版本。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Palo Alto Networks | PAN-OS | 8.1.* | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | Exploit to capitalize on vulnerability CVE-2020-2038. | https://github.com/und3sc0n0c1d0/CVE-2020-2038 | POC Details |
No public POC found.
Login to generate AI POC| CVE-2020-2040 | 9.8 CRITICAL | PAN-OS: Buffer overflow when Captive Portal or Multi-Factor Authentication (MFA) is enable |
| CVE-2020-2036 | 8.8 HIGH | PAN-OS: Reflected Cross-Site Scripting (XSS) vulnerability in management web interface |
| CVE-2020-2041 | 7.5 HIGH | PAN-OS: Management web interface denial-of-service (DoS) |
| CVE-2020-2037 | 7.2 HIGH | PAN-OS: OS command injection vulnerability in the management web interface |
| CVE-2020-2042 | 7.2 HIGH | PAN-OS: Buffer overflow in the management web interface |
| CVE-2020-2039 | 5.3 MEDIUM | PAN-OS: Management web interface denial-of-service (DoS) through unauthenticated file uplo |
| CVE-2020-2043 | 3.3 LOW | PAN-OS: Passwords may be logged in clear text when using after-change-detail custom syslog |
| CVE-2020-2044 | 3.3 LOW | PAN-OS: Passwords may be logged in clear text while storing operational command (op comman |
No comments yet