HomeSecurityPalo Alto Networks fixes critical vulnerabilities in PAN-OS

Palo Alto Networks fixes critical vulnerabilities in PAN-OS

PAN-OS

Palo Alto Networks has released updates security and fixed critical vulnerabilities in its PAN-OS firewall softwarethat could allow malicious code execution and denial-of-service (DoS) attacks.

The most serious vulnerability was a “buffer overflow” issue that could be exploited by a remote, unauthorized user to interrupt system processes and execute code with root privileges.

The vulnerability has been named CVE-2020-2040 and could be exploited by sending specially crafted requests to the Multi-Factor Authentication (MFA) interface or Captive Portal.

This vulnerability was rated 9.8 on the CVSS scale and affects all PAN-OS 8.0 versions, 8.1 versions before 8.1.15, PAN-OS 9.0 versions before 9.0.9, and PAN-OS 9.1 versions before 9.1.3.

Another serious vulnerability that Palo Alto Networks has patched is a “Reflected Cross-Site Scripting” (XSS) issue in PAN-OS. The vulnerability has been labeled CVE-2020-2036 and is located in the management web interface.

A remote attacker can convince an administrator in the firewall management interface to click on a crafted link to that management web interface. If this is done, the hacker could potentially execute JavaScript code in the browser administrator's and perform actions that only the administrator could.

This vulnerability is rated 8.8 on the CVSS scale and affects all PAN-OS 8.1 versions before 8.1.16 and PAN-OS 9.0 versions before 9.0.9.

Palo Alto Networks

Palo Alto Networks also patched a vulnerability, which has been named CVE-2020-2041 , that could allow a denial-of-service attack.

An insecure configuration of the Palo Alto Networks PAN-OS 8.1 appweb daemon allows a remote, unauthorized user to send a specially crafted request to the device, which will cause the appweb service to stop working,” the company says. “Repeated attempts to send this request lead to a denial of service to all services , causing the device to reboot and put it into maintenance mode.”

The full list of vulnerabilities fixed by the companyis available here.

Palo Alto Networks says it has found no evidence that vulnerabilities in its PAN-OS firewall software have been exploited by hackers.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS