CVE-2020-2011 is an improper input validation vulnerability in Palo Alto Networks PAN-OS Panorama that allows a remote, unauthenticated attacker to crash the configuration service and trigger a denial of service by repeatedly sending a specially crafted registration request. This affects various versions of PAN-OS 7.1, 8.0, 8.1 (prior to 8.1.14), 9.0 (prior to 9.0.7), and 9.1 (prior to 9.1.0). With a CVSS score of 7.5 (High), the vulnerability is easily exploitable over the network with low attack complexity, leading to a complete loss of availability for affected services. There is no evidence of active exploitation, public exploit code, or Metasploit modules, though it has received some community and media attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 7.1.0, <= 7.1.26CPE matchmatch criteria | cpe:2.3:o:paloaltonetworks:pan-os:*:*:*:*:*:*:*:* | ||
>= 8.0.0, <= 8.0.20CPE matchmatch criteria | cpe:2.3:o:paloaltonetworks:pan-os:*:*:*:*:*:*:*:* | ||
>= 8.1.0, < 8.1.14CPE matchmatch criteria | cpe:2.3:o:paloaltonetworks:pan-os:*:*:*:*:*:*:*:* | ||
>= 9.0.0, < 9.1.0CPE matchmatch criteria | cpe:2.3:o:paloaltonetworks:pan-os:*:*:*:*:*:*:*:* | ||
>= 8.1, < 8.1.14CPE match | cpe:2.3:o:paloaltonetworks:pan-os:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.