← Back to browse · API

CVE-2020-2038

Severity
HIGH
CVSS
7.2
EPSS
0.86086
Risk score
58.93
CISA KEV
No
PoC
No
Published
2020-09-09
Modified
2024-09-16
First seen
2026-08-07
Aliases
EUVD-2020-22064, GHSA-QQ25-3QFM-WPJJ
Products
Palo Alto Networks:PAN-OS 10.0 <10.0.1, Palo Alto Networks:PAN-OS 9.0 <9.0.10, Palo Alto Networks:PAN-OS 9.1 <9.1.4
Sources
euvd EUVD-2020-22064

Description

An OS Command Injection vulnerability in the PAN-OS management interface that allows authenticated administrators to execute arbitrary OS commands with root privileges. This issue impacts: PAN-OS 9.0 versions earlier than 9.0.10; PAN-OS 9.1 versions earlier than 9.1.4; PAN-OS 10.0 versions earlier than 10.0.1.

References