Vulnerability Details CVE-2020-2038
An OS Command Injection vulnerability in the PAN-OS management interface that allows authenticated administrators to execute arbitrary OS commands with root privileges. This issue impacts: PAN-OS 9.0 versions earlier than 9.0.10; PAN-OS 9.1 versions earlier than 9.1.4; PAN-OS 10.0 versions earlier than 10.0.1.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.925
EPSS Ranking 99.7%
CVSS Severity
CVSS v3 Score 7.2
CVSS v2 Score 9.0
Products affected by CVE-2020-2038
-
cpe:2.3:o:paloaltonetworks:pan-os:10.0.0
-
cpe:2.3:o:paloaltonetworks:pan-os:9.0.0
-
cpe:2.3:o:paloaltonetworks:pan-os:9.0.1
-
cpe:2.3:o:paloaltonetworks:pan-os:9.0.2
-
cpe:2.3:o:paloaltonetworks:pan-os:9.0.3
-
cpe:2.3:o:paloaltonetworks:pan-os:9.0.4
-
cpe:2.3:o:paloaltonetworks:pan-os:9.0.5
-
cpe:2.3:o:paloaltonetworks:pan-os:9.0.6
-
cpe:2.3:o:paloaltonetworks:pan-os:9.0.7
-
cpe:2.3:o:paloaltonetworks:pan-os:9.0.8
-
cpe:2.3:o:paloaltonetworks:pan-os:9.0.9
-
cpe:2.3:o:paloaltonetworks:pan-os:9.1.0
-
cpe:2.3:o:paloaltonetworks:pan-os:9.1.1
-
cpe:2.3:o:paloaltonetworks:pan-os:9.1.2
-
cpe:2.3:o:paloaltonetworks:pan-os:9.1.3