CVE-2020-2021 is a critical vulnerability in Palo Alto Networks PAN-OS that allows unauthenticated network-based attackers to bypass SAML authentication when the "Validate Identity Provider Certificate" option is disabled. This affects PAN-OS versions 9.1 (earlier than 9.1.3), 9.0 (earlier than 9.0.9), 8.1 (earlier than 8.1.15), and all 8.0 versions. The vulnerability has a CVSS score of 10.0, indicating a critical severity due to its network-based attack vector, low complexity, and potential for full compromise of protected resources or administrative access to PAN-OS/Panorama web interfaces. This CVE is actively exploited, listed in the KEV catalog, and has garnered significant community attention and media coverage, despite no public exploit code being readily available.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 8.0.0, <= 8.0.20CPE matchmatch criteria | cpe:2.3:o:paloaltonetworks:pan-os:*:*:*:*:*:*:*:* | ||
>= 8.1.0, < 8.1.15CPE matchmatch criteria | cpe:2.3:o:paloaltonetworks:pan-os:*:*:*:*:*:*:*:* | ||
>= 9.0.0, < 9.0.9CPE matchmatch criteria | cpe:2.3:o:paloaltonetworks:pan-os:*:*:*:*:*:*:*:* | ||
>= 9.1.0, < 9.1.3CPE matchmatch criteria | cpe:2.3:o:paloaltonetworks:pan-os:*:*:*:*:*:*:*:* | ||
>= 8.1, < 8.1.15CPE match | cpe:2.3:o:paloaltonetworks:pan-os:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.