CVE-2020-2009 is an external control of filename vulnerability affecting the SD WAN component of Palo Alto Networks PAN-OS Panorama, specifically versions 7.1 (all), 8.1 (prior to 8.1.14), and 9.0 (prior to 9.0.7). An authenticated administrator can exploit this to create and write arbitrary files on managed firewalls, potentially leading to arbitrary code execution with root privileges. With a CVSS score of 7.2 (High), this vulnerability has a network attack vector and low attack complexity, allowing for high impact on confidentiality, integrity, and availability. The EPSS score is low at 0.01523, suggesting a low probability of exploitation in the wild. Currently, there is no evidence of active exploitation, nor is public exploit code available in Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage for this CVE are minimal, aligning with the typical low attention for most vulnerabilities.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 7.1.0, <= 7.1.26CPE matchmatch criteria | cpe:2.3:o:paloaltonetworks:pan-os:*:*:*:*:*:*:*:* | ||
>= 8.0.0, <= 8.0.20CPE matchmatch criteria | cpe:2.3:o:paloaltonetworks:pan-os:*:*:*:*:*:*:*:* | ||
>= 8.1.0, <= 8.1.13CPE matchmatch criteria | cpe:2.3:o:paloaltonetworks:pan-os:*:*:*:*:*:*:*:* | ||
>= 9.0.0, <= 9.0.6CPE matchmatch criteria | cpe:2.3:o:paloaltonetworks:pan-os:*:*:*:*:*:*:*:* | ||
>= 8.1, < 8.1.14CPE match | cpe:2.3:o:paloaltonetworks:pan-os:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.3 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.