← voltar
CVE-2020-2043

PAN-OS: Passwords may be logged in clear text when using after-change-detail custom syslog field for config logs

CVSS 3.3 LOWEPSS 0.7%CWE-532
Vexday Risk Score
8Baixo
Decisão SSVC (CISA)
Track
Sem sinal de exploração → monitorar
CVSS 3.3EPSS 0.7%KEV nãoPoC Nuclei Metasploit Patch
Ciclo de vida
09 set 2020Publicada no NVD
Recomendação: Monitorar — sem sinal de exploração no momento.
An information exposure through log file vulnerability where sensitive fields are recorded in the configuration log without masking on Palo Alto Networks PAN-OS software when the after-change-detail custom syslog field is enabled for configuration logs and the sensitive field appears multiple times in one log entry. The first instance of the sensitive field is masked but subsequent instances are left in clear text. This issue impacts: PAN-OS 8.1 versions earlier than PAN-OS 8.1.16; PAN-OS 9.0 versions earlier than PAN-OS 9.0.10; PAN-OS 9.1 versions earlier than PAN-OS 9.1.4.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Quer saber se a sua infraestrutura está exposta a isto?

Falar com a TrueHacking →