code | #
# (C) Tenable Network Security, Inc.
#
include('compat.inc');
if (description)
{
script_id(136816);
script_version("1.2");
script_set_attribute(attribute:"plugin_modification_date", value:"2020/07/03");
script_cve_id("CVE-2020-2012");
script_xref(name:"IAVA", value:"2020-A-0222-S");
script_name(english:"Palo Alto Networks PAN-OS 7.1.x < 8.1.13 / 8.0.x < 8.1.13 / 8.1.x < 8.1.13 / 9.0.x < 9.0.7 Vulnerability");
script_set_attribute(attribute:"synopsis", value:
"The remote PAN-OS host is affected by vulnerability");
script_set_attribute(attribute:"description", value:
"The version of Palo Alto Networks PAN-OS running on the remote host is 7.1.x prior to 8.1.13 or 8.0.x prior to 8.1.13 or
8.1.x prior to 8.1.13 or 9.0.x prior to 9.0.7. It is, therefore, affected by a vulnerability.
- Improper restriction of XML external entity reference
('XXE') vulnerability in Palo Alto Networks Panorama
management service allows remote unauthenticated
attackers with network access to the Panorama management
interface to read arbitrary files on the system. This
issue affects: All versions of PAN-OS for Panorama 7.1
and 8.0; PAN-OS for Panorama 8.1 versions earlier than
8.1.13; PAN-OS for Panorama 9.0 versions earlier than
9.0.7. (CVE-2020-2012)
Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version
number.");
script_set_attribute(attribute:"see_also", value:"https://security.paloaltonetworks.com/CVE-2020-2012");
script_set_attribute(attribute:"see_also", value:"https://cwe.mitre.org/data/definitions/611.html");
script_set_attribute(attribute:"solution", value:
"Upgrade to PAN-OS 8.1.13 / 8.1.13 / 8.1.13 / 9.0.7 or later");
script_set_cvss_base_vector("CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:N");
script_set_cvss3_base_vector("CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N");
script_set_attribute(attribute:"cvss_score_source", value:"CVE-2020-2012");
script_cwe_id(611);
script_set_attribute(attribute:"vuln_publication_date", value:"2020/05/13");
script_set_attribute(attribute:"patch_publication_date", value:"2020/05/13");
script_set_attribute(attribute:"plugin_publication_date", value:"2020/05/22");
script_set_attribute(attribute:"plugin_type", value:"combined");
script_set_attribute(attribute:"cpe", value:"cpe:/o:paloaltonetworks:pan-os");
script_set_attribute(attribute:"stig_severity", value:"I");
script_end_attributes();
script_category(ACT_GATHER_INFO);
script_family(english:"Palo Alto Local Security Checks");
script_copyright(english:"This script is Copyright (C) 2020 and is owned by Tenable, Inc. or an Affiliate thereof.");
script_dependencies("palo_alto_version.nbin");
script_require_keys("Host/Palo_Alto/Firewall/Version", "Host/Palo_Alto/Firewall/Full_Version", "Host/Palo_Alto/Firewall/Source");
exit(0);
}
include('vcf.inc');
include('vcf_extras.inc');
vcf::palo_alto::initialize();
app_name = 'Palo Alto Networks PAN-OS';
app_info = vcf::get_app_info(app:app_name, kb_ver:'Host/Palo_Alto/Firewall/Full_Version', kb_source:'Host/Palo_Alto/Firewall/Source');
constraints = [
{ 'min_version' : '7.1.0', 'fixed_version' : '8.1.13' },
{ 'min_version' : '8.0.0', 'fixed_version' : '8.1.13' },
{ 'min_version' : '8.1.0', 'fixed_version' : '8.1.13' },
{ 'min_version' : '9.0.0', 'fixed_version' : '9.0.7' }
];
vcf::check_version_and_report(app_info:app_info, constraints:constraints, severity:SECURITY_WARNING);
|