Record summary

CVE-2020-2034 has a selected CVSS score of 8.1 (high); EIP currently links 1 repository PoC.

Description

An OS Command Injection vulnerability in the PAN-OS GlobalProtect portal allows an unauthenticated network based attacker to execute arbitrary OS commands with root privileges. An attacker requires some knowledge of the firewall to exploit this issue. This issue can not be exploited if GlobalProtect portal feature is not enabled. This issue impacts PAN-OS 9.1 versions earlier than PAN-OS 9.1.3; PAN-OS 8.1 versions earlier than PAN-OS 8.1.15; PAN-OS 9.0 versions earlier than PAN-OS 9.0.9; all versions of PAN-OS 8.0 and PAN-OS 7.1. Prisma Access services are not impacted by this vulnerability.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Jul 31, 2025 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Repository PoCs
1

Affected products and versions

1
ProductSourceVersion rangeStatus
VulnCheck, CVE List8.0.*affected
7.1.*affected
9.1 to < 9.1.3affected
9.0 to < 9.0.9affected
8.1 to < 8.1.15affected

Proofs of concept

1

Repository PoCs

GitHubblackhatethicalhacking/CVE-2020-2034-POCRepository PoCby blackhatethicalhackingStars: 12Not analyzed4 files

14.4 KiB

GitHub

PoC details

References

2