Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2020-2035

Опубликовано: 12 авг. 2020
Источник: nvd
CVSS3: 3
CVSS2: 3.5
EPSS Низкий

Описание

When SSL/TLS Forward Proxy Decryption mode has been configured to decrypt the web transactions, the PAN-OS URL filtering feature inspects the HTTP Host and URL path headers for policy enforcement on the decrypted HTTPS web transactions but does not consider Server Name Indication (SNI) field within the TLS Client Hello handshake. This allows a compromised host in a protected network to evade any security policy that uses URL filtering on a firewall configured with SSL Decryption in the Forward Proxy mode. A malicious actor can then use this technique to evade detection of communication on the TLS handshake phase between a compromised host and a remote malicious server. This technique does not increase the risk of a host being compromised in the network. It does not impact the confidentiality or availability of a firewall. This is considered to have a low impact on the integrity of the firewall because the firewall fails to enforce a policy on certain traffic that should have been block

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:o:paloaltonetworks:pan-os:*:*:*:*:*:*:*:*

EPSS

Процентиль: 49%
0.00263
Низкий

3 Low

CVSS3

3.5 Low

CVSS2

Дефекты

CWE-20
NVD-CWE-noinfo

Связанные уязвимости

github
больше 3 лет назад

When SSL/TLS Forward Proxy Decryption mode has been configured to decrypt the web transactions, the PAN-OS URL filtering feature inspects the HTTP Host and URL path headers for policy enforcement on the decrypted HTTPS web transactions but does not consider Server Name Indication (SNI) field within the TLS Client Hello handshake. This allows a compromised host in a protected network to evade any security policy that uses URL filtering on a firewall configured with SSL Decryption in the Forward Proxy mode. A malicious actor can then use this technique to evade detection of communication on the TLS handshake phase between a compromised host and a remote malicious server. This technique does not increase the risk of a host being compromised in the network. It does not impact the confidentiality or availability of a firewall. This is considered to have a low impact on the integrity of the firewall because the firewall fails to enforce a policy on certain traffic that should have been bl...

EPSS

Процентиль: 49%
0.00263
Низкий

3 Low

CVSS3

3.5 Low

CVSS2

Дефекты

CWE-20
NVD-CWE-noinfo