Vulnerabilities > CVE-2020-1995 - NULL Pointer Dereference vulnerability in Paloaltonetworks Pan-Os 9.1.0/9.1.1
Attack vector
NETWORK Attack complexity
LOW Privileges required
HIGH Confidentiality impact
NONE Integrity impact
NONE Availability impact
HIGH Summary
A NULL pointer dereference vulnerability in Palo Alto Networks PAN-OS allows an authenticated administrator to send a request that causes the rasmgr daemon to crash. Repeated attempts to send this request result in denial of service to all PAN-OS services by restarting the device and putting it into maintenance mode. This issue affects: PAN-OS 9.1 versions earlier than 9.1.2.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
OS | 2 |
Common Weakness Enumeration (CWE)
Nessus
NASL family | Palo Alto Local Security Checks |
NASL id | PALO_ALTO_CVE-2020-1995.NASL |
description | The version of Palo Alto Networks PAN-OS running on the remote host is 9.1.x prior to 9.1.2. It is, therefore, affected by a vulnerability. - A NULL pointer dereference vulnerability in Palo Alto Networks PAN-OS allows an authenticated administrator to send a request that causes the rasmgr daemon to crash. Repeated attempts to send this request result in denial of service to all PAN-OS services by restarting the device and putting it into maintenance mode. This issue affects: PAN-OS 9.1 versions earlier than 9.1.2. (CVE-2020-1995) Note that Nessus has not tested for this issue but has instead relied only on the application |
last seen | 2020-05-23 |
modified | 2020-05-21 |
plugin id | 136762 |
published | 2020-05-21 |
reporter | This script is Copyright (C) 2020 and is owned by Tenable, Inc. or an Affiliate thereof. |
source | https://www.tenable.com/plugins/nessus/136762 |
title | Palo Alto Networks PAN-OS 9.1.x < 9.1.2 Vulnerability |
code |
|