Palo Alto Networks (PAN) today addressed another serious vulnerability identified in the PAN-OS GlobalProtect gateway, affecting unpatched PAN next-generation firewalls.
On June 29, PAN also fixed a critical vulnerability (CVE-2020-2021) with a CVSSv3 score of 10/10, allowing unauthorized attackers to bypass authentication on PAN-OS devices with SAML authentication enabled and the “Validate Identity Provider Certificate” option disabled.
The OS command injection vulnerability patched today and tracked as CVE-2020-2034 allows unauthenticated remote attackers to execute arbitrary operating system commands with root privileges on unconnected devices.
The CVE-2020-2034 vulnerability has been rated as high severity with a CVSS 3.x base score of 8.1 and can be exploited by threat actors with network access to vulnerable servers as part of highly sophisticated attacks that do not require user interaction.

Only affects devices with GlobalProtect gateway enabled
“This issue cannot be exploited if the feature ,” explains PAN’s security advisory. “Prisma Access services are not affected by this vulnerability.”
The table below lists the affected PAN-OS versions, as well as those that received patches from Palo Alto Networks to defend against potential attacks (the issue is resolved in PAN-OS 8.1.15, PAN-OS 9.0.9, PAN-OS 9.1.3, and all later versions.)
PAN-OS 7.1 and PAN-OS 8.0 are at the end of lifecycle and will not receive security updates to address this vulnerability.
The vulnerability was discovered by Yamata Li of Palo Alto Networks Threat Research Team during an internal security.
Attackers need additional knowledge to exploit
"An attacker would require some level of specific information about the configuration of an affected firewall or perform brute-force attacks to exploit this issue," Palo Alto Networks' security advisory states.
Although the PAN does not explain what specific information attackers would need to know about vulnerable devices to successfully exploit the vulnerability, Nate Warfield of the CTI League said this could mean attacks would need to be tailored per device.
“Attack Complexity is a bit vague, and high complexity can mean different things depending on what the vulnerability is, what the product is, and the level of complexity the vendor assumes it is to exploit,” Warfield told BleepingComputer when asked to explain the phrase “attacks are tailored per device.”.
“Low level of complexity are vulnerabilities like MS17-010, SMBGhost, etc. that only need the device to be exposed to be exploitable.
“Complexity could be either “modify memory offsets in POC based on number of CPUs/memory” or it could be something else, so the measurement is very subjective.”
