CVE-2020-1977 - CVE House
Back to Database
Status published High CVE-2020-1977

Expedition Migration Tool: Insufficient Cross Site Request Forgery protection.

Vulnerability Description

Insufficient Cross-Site Request Forgery (XSRF) protection on Expedition Migration Tool allows remote unauthenticated attackers to hijack the authentication of administrators and to perform actions on the Expedition Migration Tool. This issue affects Expedition Migration Tool 1.1.51 and earlier versions.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2020-1977

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • Palo Alto Networks thanks Jimi Sebree of Tenable Research for discovering and responsibly reporting this issue.

Affected Vendor

Palo Alto Networks

View all reports →

Affected Software

Expedition
Vulnerable Versions:
1.1

Timeline

Official Publish: February 12th, 2020
Last Modified: September 17th, 2024
Added to House: July 21st, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

Weaknesses (CWE)