CVE-2020-2040 is a critical buffer overflow vulnerability in Palo Alto Networks PAN-OS that allows unauthenticated attackers to disrupt system processes and potentially execute arbitrary code with root privileges. This affects various versions of PAN-OS 8.0, 8.1, 9.0, and 9.1. With a CVSS score of 9.8 (Critical), it has a network attack vector, low attack complexity, and high impact on confidentiality, integrity, and availability. While not listed in CISA KEV, there is no public exploit code (Metasploit, Nuclei, ExploitDB), but it has garnered significant community discussion and media coverage, indicating awareness of its severity.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 8.0.0, <= 8.0.20CPE matchmatch criteria | cpe:2.3:o:paloaltonetworks:pan-os:*:*:*:*:*:*:*:* | ||
>= 8.1.0, < 8.1.15CPE matchmatch criteria | cpe:2.3:o:paloaltonetworks:pan-os:*:*:*:*:*:*:*:* | ||
>= 9.0.0, < 9.0.9CPE matchmatch criteria | cpe:2.3:o:paloaltonetworks:pan-os:*:*:*:*:*:*:*:* | ||
>= 9.1.0, < 9.1.3CPE matchmatch criteria | cpe:2.3:o:paloaltonetworks:pan-os:*:*:*:*:*:*:*:* | ||
>= 8.1, < 8.1.15CPE match | cpe:2.3:o:paloaltonetworks:pan-os:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.