Palo Alto Networks Security Advisories / CVE-2020-1995

CVE-2020-1995 PAN-OS: Management server rasmgr denial of service

047910
Severity 4.9 · MEDIUM
Attack Vector NETWORK
Attack Complexity LOW
Privileges Required HIGH
User Interaction NONE
Scope UNCHANGED
Confidentiality Impact NONE
Integrity Impact NONE
Availability Impact HIGH

Description

A NULL pointer dereference vulnerability in Palo Alto Networks PAN-OS allows an authenticated administrator to send a request that causes the rasmgr daemon to crash. Repeated attempts to send this request result in denial of service to all PAN-OS services by restarting the device and putting it into maintenance mode.

This issue affects:

PAN-OS 9.1 versions earlier than 9.1.2.

Product Status

PAN-OS

VersionsAffectedUnaffected
9.1< 9.1.2>= 9.1.2

Severity: MEDIUM

CVSSv3.1 Base Score: 4.9 (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H)

Weakness Type

CWE-476 NULL Pointer Dereference

Solution

This issue is fixed in PAN-OS 9.1.2 and all later PAN-OS versions.

Workarounds and Mitigations

Acknowledgments

This issue was found by Nicholas Newsom of Palo Alto Networks during internal security review.

Timeline

Initial publication
© 2020 Palo Alto Networks, Inc. All rights reserved.