CVE-2020-1996

MEDIUM

PAN-OS 7.1.0-7.1.25 - Unauthenticated Log Injection in Management Server

Title source: llm
STIX 2.1

Description

A missing authorization vulnerability in the management server component of PAN-OS Panorama allows a remote unauthenticated user to inject messages into the management server ms.log file. This vulnerability can be leveraged to obfuscate an ongoing attack or fabricate log entries in the ms.log file This issue affects: All versions of PAN-OS 7.1 and 8.0; PAN-OS 8.1 versions earlier than 8.1.14; PAN-OS 9.0 versions earlier than 9.0.9.

References (1)

Core 1
Core References
Vendor Advisory x_refsource_misc
https://security.paloaltonetworks.com/CVE-2020-1996

Scores

CVSS v3 5.3
EPSS 0.0070
EPSS Percentile 72.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

Details

CWE
CWE-862
Status published
Products (1)
paloaltonetworks/pan-os 7.1.0 - 7.1.26
Published May 13, 2020
Tracked Since Feb 18, 2026