Palo Alto Update
2580Warning Date
Severity Level
Warning Number
Target Sector
9 April, 2020
● High
2020-1121
All
Description:
Palo Alto has released security updates to address several vulnerabilities in the following products:
- Secdo
- PAN-OS
- GlobalProtect Agent
- Traps
- VM-Series Plugin
Threats:
Attacker could exploit these vulnerabilites by doing the following:
- Denial of service attack (DoS) -remotely
- Escalation of privilege
- Buffer overflow
- Unauthorized disclosure of information
Best practice and Recommendations:
The CERT team encourages users to review Palo Alto security advisory and apply the necessary updates:
- https://security.paloaltonetworks.com/CVE-2020-1992
- https://security.paloaltonetworks.com/CVE-2020-1990
- https://security.paloaltonetworks.com/CVE-2020-1987
- https://security.paloaltonetworks.com/CVE-2020-1989
- https://security.paloaltonetworks.com/CVE-2020-1988
- https://security.paloaltonetworks.com/CVE-2020-1985
- https://security.paloaltonetworks.com/CVE-2020-1986
- https://security.paloaltonetworks.com/PAN-SA-2020-0002
- https://security.paloaltonetworks.com/CVE-2020-1991
- https://security.paloaltonetworks.com/CVE-2020-1978
- https://security.paloaltonetworks.com/CVE-2020-1984