Vulnerabilities > CVE-2020-1981 - Exposure of Resource to Wrong Sphere vulnerability in Paloaltonetworks Pan-Os
Attack vector
LOCAL Attack complexity
LOW Privileges required
LOW Confidentiality impact
HIGH Integrity impact
HIGH Availability impact
HIGH Summary
A predictable temporary filename vulnerability in PAN-OS allows local privilege escalation. This issue allows a local attacker who bypassed the restricted shell to execute commands as a low privileged user and gain root access on the PAN-OS hardware or virtual appliance. This issue affects only PAN-OS 8.1 versions earlier than PAN-OS 8.1.13. This issue does not affect PAN-OS 7.1, PAN-OS 9.0, or later PAN-OS versions.
Vulnerable Configurations
Common Weakness Enumeration (CWE)
Nessus
NASL family | Palo Alto Local Security Checks |
NASL id | PALO_ALTO_CVE-2020-1981.NASL |
description | The version of Palo Alto Networks PAN-OS running on the remote host is 8.1.x prior to 8.1.13. It is, therefore, affected by a vulnerability. - A predictable temporary filename vulnerability in PAN-OS allows local privilege escalation. This issue allows a local attacker who bypassed the restricted shell to execute commands as a low privileged user and gain root access on the PAN-OS hardware or virtual appliance. This issue affects only PAN-OS 8.1 versions earlier than PAN- OS 8.1.13. This issue does not affect PAN-OS 7.1, PAN-OS 9.0, or later PAN-OS versions. (CVE-2020-1981) Note that Nessus has not tested for this issue but has instead relied only on the application |
last seen | 2020-05-23 |
modified | 2020-03-19 |
plugin id | 134710 |
published | 2020-03-19 |
reporter | This script is Copyright (C) 2020 and is owned by Tenable, Inc. or an Affiliate thereof. |
source | https://www.tenable.com/plugins/nessus/134710 |
title | Palo Alto Networks PAN-OS 8.1.x < 8.1.13 Vulnerability |
code |
|