← back
CVE-2020-1993

PAN-OS: GlobalProtect Portal PHP session fixation vulnerability

CVSS 3.7 LOWEPSS 0.4%CWE-384
Vexday Risk Score
8Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 3.7EPSS 0.4%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
13 May 2020Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
The GlobalProtect Portal feature in PAN-OS does not set a new session identifier after a successful user login, which allows session fixation attacks, if an attacker is able to control a user's session ID. This issue affects: All PAN-OS 7.1 and 8.0 versions; PAN-OS 8.1 versions earlier than 8.1.14; PAN-OS 9.0 versions earlier than 9.0.8.
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:N

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →