CVE-2020-2002 is an authentication bypass vulnerability in Palo Alto Networks PAN-OS, affecting versions 7.1, 8.0, 8.1, and 9.0. It allows a man-in-the-middle attacker to spoof Kerberos authentication, enabling unauthorized administrative access to PAN-OS. The vulnerability has a CVSS score of 8.1 (High), indicating a network-based attack with high impact on confidentiality, integrity, and availability, but requiring high attack complexity. While there is no known active exploitation or public exploit code, the vulnerability has garnered significant community discussion and media coverage, suggesting awareness and potential interest from threat actors.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 7.1.0, < 7.1.26CPE matchmatch criteria | cpe:2.3:o:paloaltonetworks:pan-os:*:*:*:*:*:*:*:* | ||
>= 8.0.0, <= 8.0.20CPE matchmatch criteria | cpe:2.3:o:paloaltonetworks:pan-os:*:*:*:*:*:*:*:* | ||
>= 8.1.0, < 8.1.13CPE matchmatch criteria | cpe:2.3:o:paloaltonetworks:pan-os:*:*:*:*:*:*:*:* | ||
>= 9.0.0, < 9.0.6CPE matchmatch criteria | cpe:2.3:o:paloaltonetworks:pan-os:*:*:*:*:*:*:*:* | ||
>= 7.1, < 7.1.26CPE match | cpe:2.3:o:paloaltonetworks:pan-os:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.