CVE-2020-2050
Last modified
CVE-2020-2050 is a high-severity vulnerability rated 8.2/10 on the CVSS scale. An authentication bypass vulnerability exists in the GlobalProtect SSL VPN component of Palo Alto Networks PAN-OS software that allows an attacker to bypass all client certificate checks with an invalid certificate. A remote attacker can successfully authenticate as any user and gain access to restricted VPN network resources when the gateway or portal is configured to rely entirely on certificate-based authentication. EPSS estimates a 1.02% chance of exploitation in the next 30 days.
Description
An authentication bypass vulnerability exists in the GlobalProtect SSL VPN component of Palo Alto Networks PAN-OS software that allows an attacker to bypass all client certificate checks with an invalid certificate. A remote attacker can successfully authenticate as any user and gain access to restricted VPN network resources when the gateway or portal is configured to rely entirely on certificate-based authentication. Impacted features that use SSL VPN with client certificate verification are: GlobalProtect Gateway, GlobalProtect Portal, GlobalProtect Clientless VPN In configurations where client certificate verification is used in conjunction with other authentication methods, the protections added by the certificate check are ignored as a result of this issue. This issue impacts: PAN-OS 8.1 versions earlier than PAN-OS 8.1.17; PAN-OS 9.0 versions earlier than PAN-OS 9.0.11; PAN-OS 9.1 versions earlier than PAN-OS 9.1.5; PAN-OS 10.0 versions earlier than PAN-OS 10.0.1.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Paloaltonetworks | Pan-Os | >= 8.1.0, < 8.1.17 |
| Paloaltonetworks | Pan-Os | >= 9.0.0, < 9.0.11 |
| Paloaltonetworks | Pan-Os | >= 9.1.0, < 9.1.5 |
| Paloaltonetworks | Pan-Os | >= 10.0.0, < 10.0.1 |
References
- https://security.paloaltonetworks.com/CVE-2020-2050Vendor Advisory
- https://security.paloaltonetworks.com/CVE-2020-2050Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2020-2050?
How severe is CVE-2020-2050?
How do I fix CVE-2020-2050?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2020
- CVE-2020-2048An information exposure through log file vulnerability exist…3.3
- CVE-2020-20486IEC104 v1.0 contains a stack-buffer overflow in the paramete…7.5
- CVE-2020-2049A local privilege escalation vulnerability exists in Palo Al…7.8
- CVE-2020-20490A heap buffer-overflow in the client_example1.c component of…7.5
- CVE-2020-20491SQL injection vulnerability in OpenCart v.2.2.00 thru 3.0.3.…7.2
- CVE-2020-20495bludit v3.13.0 contains an arbitrary file deletion vulnerabi…9.1
- CVE-2020-20502Cross Site Request Forgery found in yzCMS v.2.0 allows a rem…6.5
- CVE-2020-20508Shopkit v2.7 contains a reflective cross-site scripting (XSS…6.1
- CVE-2020-2051Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2020-20514A Cross-Site Request Forgery (CSRF) in Maccms v10 via admin.…8.1
- CVE-2020-2052Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2020-20521Cross Site Scripting vulnerability found in KiteCMS v.1.1 al…6.1
Are you affected by CVE-2020-2050?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
