CVE-2020-2021

Palo Alto Networks PAN-OS: Authentication Bypass

As of , CVE-2020-2021 in Palo Alto Networks PAN-OS is on CISA's list of exploited vulnerabilities: CISA listed it on . Our patch-first group: Patch this week.

Exploited
Yes: CISA listed it on 25 March 2022
US federal deadline
15 April 202221 days after CISA listed it. US federal civilian agencies must fix it by then.
Used in ransomware campaigns
Known
EPSS score
0.04Higher than 90% of the CVEs EPSS scores. EPSS estimates the chance of exploitation activity in the next 30 days.
EPSS when listed
0.11 on 25 March 2022EPSS on the day CISA listed it.
Public exploit
None foundNeither Metasploit nor Exploit-DB lists one.
Fix
No vendor link in CISA's entry

What CISA says to do

Apply updates per vendor instructions.

CISA's required action

What the flaw is

Palo Alto Networks PAN-OS contains a vulnerability in SAML which allows an attacker to bypass authentication.

CISA's description

When Security Assertion Markup Language (SAML) authentication is enabled and the 'Validate Identity Provider Certificate' option is disabled (unchecked), improper verification of signatures in PAN-OS SAML authentication enables an unauthenticated network-based attacker to access protected resources. The attacker must have network access to the vulnerable server to exploit this vulnerability. This issue affects PAN-OS 9.1 versions earlier than PAN-OS 9.1.3; PAN-OS 9.0 versions earlier than PAN-OS 9.0.9; PAN-OS 8.1 versions earlier than PAN-OS 8.1.15, and all versions of PAN-OS 8.0 (EOL). This issue does not affect PAN-OS 7.1. This issue cannot be exploited if SAML is not used for authentication. This issue cannot be exploited if the 'Validate Identity Provider Certificate' option is enabled (checked) in the SAML Identity Provider Server Profile. Resources that can be protected by SAML-based single sign-on (SSO) authentication are: GlobalProtect Gateway, GlobalProtect Portal, GlobalProtect Clientless VPN, Authentication and Captive Portal, PAN-OS next-generation firewalls (PA-Series, VM-Series) and Panorama web interfaces, Prisma Access In the case of GlobalProtect Gateways, GlobalProtect Portal, Clientless VPN, Captive Portal, and Prisma Access, an unauthenticated attacker with network access to the affected servers can gain access to protected resources if allowed by configured authentication and Security policies.

The CVE record's description, from palo_alto, shortened; full text on cve.org

CVE published
29 June 2020
Assigned by
palo_alto
CVSS
10.0 Critical (CVSS 3.1, from the CNA)
CWE-347
Improper Verification of Cryptographic Signature
CISA SSVC, exploitation
active
CISA SSVC, automatable
yes
CISA SSVC, technical impact
total

Timeline

  1. The CVE record was published.
  2. CISA added it to its list of exploited vulnerabilities.
  3. The US federal deadline to fix it.

PAN-OS: other exploited entries

VulnerabilityProductOur groupListedDeadlineEPSS
CVE-2026-0257Authentication BypassPalo Alto Networks PAN-OSPatch nowRansomware use, listed within a year0.97
CVE-2017-15944Remote Code ExecutionPalo Alto Networks PAN-OSPatch this weekMetasploit module; EPSS 0.98; verified Exploit-DB entry0.98
CVE-2024-0012Management Interface Authentication BypassPalo Alto Networks PAN-OSPatch this weekRansomware use; Metasploit module; EPSS 0.990.99
CVE-2024-9474Management Interface OS Command InjectionPalo Alto Networks PAN-OSPatch this weekRansomware use; Metasploit module; EPSS 0.950.95
CVE-2024-3400Command InjectionPalo Alto Networks PAN-OSPatch this weekRansomware use; Metasploit module; EPSS 0.990.99
CVE-2025-0108Authentication BypassPalo Alto Networks PAN-OSPatch this weekEPSS 0.980.98
CVE-2019-1579Remote Code ExecutionPalo Alto Networks PAN-OSPatch this weekRansomware use0.46
CVE-2026-0300Out-of-bounds WritePalo Alto Networks PAN-OSPatch soon0.32
CVE-2024-3393Malicious DNS PacketPalo Alto Networks PAN-OSPatch soon0.29
CVE-2022-0028Reflected Amplification Denial-of-ServicePalo Alto Networks PAN-OSPatch soon0.03

All 12 entries for PAN-OS

Read further