LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2020-2021: Palo Alto Networks PAN-OS Authentication Bypass Vulnerability

RBRecent Breaches Vulnerability Intelligence·Mar 25, 2022
Critical⚠ Actively exploited (CISA KEV)Ransomware-linked
Critical
Severity
Active
CISA KEV
Yes
Ransomware use
Apr 15, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2020-2021 to its Known Exploited Vulnerabilities catalog on Mar 25, 2022, with a federal patch deadline of Apr 15, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately. Ransomware crews are known to exploit this flaw.

Palo Alto Networks PAN-OS contains a vulnerability in SAML which allows an attacker to bypass authentication.

CVE-2020-2021 is an authentication bypass vulnerability in Palo Alto Networks PAN-OS that affects SAML-based authentication. An attacker who can reach the vulnerable interface may bypass normal login controls and gain unauthorized access. CISA notes known ransomware use of this issue, so organizations running PAN-OS should treat it as high priority and confirm exposure against the vendor advisory.

Because PAN-OS commonly sits at the network edge as a firewall or VPN gateway, successful abuse can give an attacker a foothold into internal networks. Defenders need to inventory affected systems, apply the vendor update, and watch for signs of unauthorized access until remediation is complete.

How it works

The weakness is classified as CWE-347 (Improper Verification of Cryptographic Signature). In SAML authentication flows, the system is supposed to cryptographically verify assertions or signatures so that only legitimate identity providers can assert a user’s identity. When verification is incomplete or incorrect, an attacker can present a crafted SAML response that the device accepts as valid.

In practical terms, an unauthenticated attacker who can reach the SAML authentication endpoint may bypass the login process entirely. Exact exploit mechanics and preconditions are not detailed here; teams must review the Palo Alto Networks advisory for the precise conditions under which the bypass succeeds. The result is unauthorized access with the privileges the SAML flow would normally grant, which on a firewall or GlobalProtect-style portal can be significant.

Am I affected? How to find it in your systems

PAN-OS runs on Palo Alto Networks next-generation firewalls, including appliances and virtual form factors that terminate VPN or provide captive-portal / SAML-based authentication. Typical locations include perimeter firewalls, data-center edge devices, and remote-access gateways that use SAML for user authentication.

How to remediate

Patching is the primary remediation. Apply the updates specified by Palo Alto Networks for CVE-2020-2021 exactly as described in the vendor advisory and follow CISA’s required action: apply updates per vendor instructions.

If you can't patch immediately

If an immediate upgrade is not possible, reduce the attack surface and increase detection until the vendor fix can be applied.

If your data may have been exposed

Actively exploited vulnerabilities, especially those with known ransomware use, frequently precede broader network compromise and data theft. If logs or other evidence suggest this CVE was abused in your environment, follow your incident-response plan: isolate affected devices, preserve forensic images and logs, reset credentials, and assess lateral movement.

As a further check on whether credentials or personal data associated with your organization have appeared in known breach corpora, you can run a free exposure scan of your email addresses against aggregated breach data sets and then force password resets and enable phishing-resistant MFA where exposure is confirmed.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedPalo Alto Networks · PAN-OS
WeaknessCWE-347
Added to CISA KEVMar 25, 2022
Federal patch deadlineApr 15, 2022
Known ransomware useYes
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities