Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2020-1978

Опубликовано: 08 апр. 2020
Источник: nvd
CVSS3: 5.8
CVSS3: 4.4
CVSS2: 1.9
EPSS Низкий

Описание

TechSupport files generated on Palo Alto Networks VM Series firewalls for Microsoft Azure platform configured with high availability (HA) inadvertently collect Azure dashboard service account credentials. These credentials are equivalent to the credentials associated with the Contributor role in Azure. A user with the credentials will be able to manage all the Azure resources in the subscription except for granting access to other resources. These credentials do not allow login access to the VMs themselves. This issue affects VM Series Plugin versions before 1.0.9 for PAN-OS 9.0. This issue does not affect VM Series in non-HA configurations or on other cloud platforms. It does not affect hardware firewall appliances. Since becoming aware of the issue, Palo Alto Networks has safely deleted all the tech support files with the credentials. We now filter and remove these credentials from all TechSupport files sent to us. The TechSupport files uploaded to Palo Alto Networks systems were onl

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:paloaltonetworks:vm-series:*:*:*:*:*:azure:*:*
Версия от 1.0 (включая) до 1.0.9 (исключая)
cpe:2.3:o:paloaltonetworks:pan-os:9.0.0:*:*:*:*:*:*:*

EPSS

Процентиль: 26%
0.00094
Низкий

5.8 Medium

CVSS3

4.4 Medium

CVSS3

1.9 Low

CVSS2

Дефекты

CWE-255
CWE-522

Связанные уязвимости

github
больше 3 лет назад

TechSupport files generated on Palo Alto Networks VM Series firewalls for Microsoft Azure platform configured with high availability (HA) inadvertently collect Azure dashboard service account credentials. These credentials are equivalent to the credentials associated with the Contributor role in Azure. A user with the credentials will be able to manage all the Azure resources in the subscription except for granting access to other resources. These credentials do not allow login access to the VMs themselves. This issue affects VM Series Plugin versions before 1.0.9 for PAN-OS 9.0. This issue does not affect VM Series in non-HA configurations or on other cloud platforms. It does not affect hardware firewall appliances. Since becoming aware of the issue, Palo Alto Networks has safely deleted all the tech support files with the credentials. We now filter and remove these credentials from all TechSupport files sent to us. The TechSupport files uploaded to Palo Alto Networks systems were ...

CVSS3: 5.8
fstec
почти 6 лет назад

Уязвимость межсетевого экрана VM-Series, связанная с недостаточной защитой регистрационных данных, позволяющая нарушителю раскрыть защищаемую информацию и вызвать отказ в обслуживании

EPSS

Процентиль: 26%
0.00094
Низкий

5.8 Medium

CVSS3

4.4 Medium

CVSS3

1.9 Low

CVSS2

Дефекты

CWE-255
CWE-522