Palo Alto Updates
3009Warning Date
Severity Level
Warning Number
Target Sector
13 February, 2020
● High
2020-910
All
Description:
Palo Alto has released security updates to address multiple vulnerabilities in the following products:
- GlobalProtect on Mac OS
- Version 5.0.5 and earlier
- Expedition Migration Tool
- Version 1.1.51 and earlier
- PAN-OS 8.1
- Versions earlier than 8.1.12
- PAN-OS 9.0
- Versions earlier than 9.0.6
Threats:
Attacker could exploit these vulnerabilities by doing the following:
- Cause the Mac OS kernel to hang or crash.
- Inject arbitrary XML that results in privilege escalation.
- Execute code in Expedition Migration Tool remotely.
Best practice and Recommendations:
The CERT team encourages users to review Palo Alto security advisory and apply the necessary updates:
- https://security.paloaltonetworks.com/CVE-2020-1976
- https://security.paloaltonetworks.com/CVE-2020-1977
- https://security.paloaltonetworks.com/CVE-2020-1975