CVE-2020-1996 is a missing authorization vulnerability in the management server component of PAN-OS Panorama, affecting all versions of PAN-OS 7.1 and 8.0, and specific earlier versions of 8.1 and 9.0. This allows an unauthenticated remote attacker to inject messages into the ms.log file. Rated as Medium severity (CVSS 5.3), the vulnerability has a low attack complexity and no user interaction required, potentially leading to log obfuscation or fabrication. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion, though it did receive some media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 7.1.0, <= 7.1.26CPE matchmatch criteria | cpe:2.3:o:paloaltonetworks:pan-os:*:*:*:*:*:*:*:* | ||
>= 8.0.0, <= 8.0.20CPE matchmatch criteria | cpe:2.3:o:paloaltonetworks:pan-os:*:*:*:*:*:*:*:* | ||
>= 8.1.0, <= 8.1.13CPE matchmatch criteria | cpe:2.3:o:paloaltonetworks:pan-os:*:*:*:*:*:*:*:* | ||
>= 9.0.0, <= 9.0.8CPE matchmatch criteria | cpe:2.3:o:paloaltonetworks:pan-os:*:*:*:*:*:*:*:* | ||
>= 8.1, < 8.1.14CPE match | cpe:2.3:o:paloaltonetworks:pan-os:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.