← Back to browse · API

CVE-2020-2040

Severity
CRITICAL
CVSS
9.8
EPSS
0.03937
Risk score
40.58
CISA KEV
No
PoC
No
Published
2020-09-09
Modified
2024-09-16
First seen
2026-08-07
Aliases
EUVD-2020-22066, GHSA-PF79-9HV7-CHG5
Products
Palo Alto Networks:PAN-OS 8.0.*, Palo Alto Networks:PAN-OS 8.1 <8.1.15, Palo Alto Networks:PAN-OS 9.0 <9.0.9, Palo Alto Networks:PAN-OS 9.1 <9.1.3
Sources
euvd EUVD-2020-22066

Description

A buffer overflow vulnerability in PAN-OS allows an unauthenticated attacker to disrupt system processes and potentially execute arbitrary code with root privileges by sending a malicious request to the Captive Portal or Multi-Factor Authentication interface. This issue impacts: All versions of PAN-OS 8.0; PAN-OS 8.1 versions earlier than PAN-OS 8.1.15; PAN-OS 9.0 versions earlier than PAN-OS 9.0.9; PAN-OS 9.1 versions earlier than PAN-OS 9.1.3.

References