CVE-2020-1977

HIGH

Expedition Migration Tool < 1.1.51 - Unauthenticated Cross-Site Request Forgery

Title source: llm
STIX 2.1

Description

Insufficient Cross-Site Request Forgery (XSRF) protection on Expedition Migration Tool allows remote unauthenticated attackers to hijack the authentication of administrators and to perform actions on the Expedition Migration Tool. This issue affects Expedition Migration Tool 1.1.51 and earlier versions.

References (2)

Core 2
Core References
Vendor Advisory x_refsource_misc
https://security.paloaltonetworks.com/CVE-2020-1977
Third Party Advisory x_refsource_misc
https://www.tenable.com/security/research/tra-2020-11

Scores

CVSS v3 7.5
EPSS 0.0019
EPSS Percentile 40.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

Details

CWE
CWE-352
Status published
Products (1)
paloaltonetworks/expedition_migration_tool 1.1 - 1.1.51
Published Feb 12, 2020
Tracked Since Feb 18, 2026