PAN-OS: GlobalProtect Portal PHP session fixation vulnerability
Vulnerability Description
The GlobalProtect Portal feature in PAN-OS does not set a new session identifier after a successful user login, which allows session fixation attacks, if an attacker is able to control a user's session ID. This issue affects: All PAN-OS 7.1 and 8.0 versions; PAN-OS 8.1 versions earlier than 8.1.14; PAN-OS 9.0 versions earlier than 9.0.8.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2020-1993
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- This issue was found by a customer.
More from Palo Alto Networks
View All →Affected Vendor
Palo Alto Networks
View all reports →