PAN-OS: Improper SAML SSO authorization of shared local users
Vulnerability Description
An improper authorization vulnerability in PAN-OS that mistakenly uses the permissions of local linux users instead of the intended SAML permissions of the account when the username is shared for the purposes of SSO authentication. This can result in authentication bypass and unintended resource access for the user. This issue affects: PAN-OS 7.1 versions earlier than 7.1.26; PAN-OS 8.1 versions earlier than 8.1.13; PAN-OS 9.0 versions earlier than 9.0.6; PAN-OS 9.1 versions earlier than 9.1.1; All versions of PAN-OS 8.0.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2020-1998
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Palo Alto Networks would like to thank Maurice Lok-Hin for discovering and reporting this issue.
More from Palo Alto Networks
View All →Affected Vendor
Palo Alto Networks
View all reports →