Palo Alto Networks Security Advisories
CVE-2020-1995 CVE-2020-1995 PAN-OS: Management server rasmgr denial of service
Attack Vector NETWORK
Attack Complexity LOW
Privileges Required HIGH
User Interaction NONE
Confidentiality Impact NONE
Integrity Impact NONE
Availability Impact HIGH NVD JSON Published 2020-05-13 Updated 2020-05-13
Reference PAN-133527 Discovered internally Description
A NULL pointer dereference vulnerability in Palo Alto Networks PAN-OS allows an authenticated administrator to send a request that causes the rasmgr daemon to crash. Repeated attempts to send this request result in denial of service to all PAN-OS services by restarting the device and putting it into maintenance mode.
This issue affects:
PAN-OS 9.1 versions earlier than 9.1.2.
Versions Affected Unaffected PAN-OS 9.1 < 9.1.2 >= 9.1.2 Severity: MEDIUM
CVSSv3.1 Base Score: 4.9 (
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H) Weakness Type CWE-476 NULL Pointer Dereference Solution
This issue is fixed in PAN-OS 9.1.2 and all later PAN-OS versions.
Workarounds and Mitigations Acknowledgments
This issue was found by Nicholas Newsom of Palo Alto Networks during internal security review.
Timeline 2020-05-13 Initial publication
© 2020 Palo Alto Networks, Inc. All rights reserved.