HC3 Sector Alert TLP White: CVE-2020-2021 PAN-OS: Authentication Bypass in SAML Authentication, June 30, 2020

On June 29, 2020, Palo Alto Networks announced a vulnerability (CVE-2020-2021) affecting their PAN-OS firewall software. The vulnerability has a 10/10 CVSSv3 score which “means the vulnerability is both easy to exploit as it doesn't require advanced technical skills, and it's remotely exploitable via the internet, without requiring attackers to gain an initial foothold on the attacked device.” Also on June 29, USCYBERCOM Cybersecurity Alert (@CNMF_CyberAlert) tweeted that they expected “Foreign APTs will likely attempt exploit soon.

Related Resources

Special Bulletin
Member
Federal agencies this morning are providing new information on an imminent ransomware threat to U.S. hospitals.
Special Bulletin
Member
The Cybersecurity and Infrastructure Security Agency (CISA), the Federal Bureau of Investigation (FBI), and the Department of Health and Human Services (HHS)…
Issue Landing Page
The number of large-scale data breaches at American health care organization increased 65% from 2010 to 2016. As a result, federal agencies are increasing…
Guides/Reports
Trusted insiders, both witting and unwitting, can cause grave harm to your organizations facilities, resources, information, and personnel. Insider incidents…
Standards/Guidelines
Public
Agent Tesla is an established Remote Access Trojan (RAT) written in .Net. A successful deployment of Agent Tesla provides attackers with full computer or…
Webinar Recordings
Public
This guide provides participants with instructions and helpful tips for the Health Sector Cybersecurity Coordination Center (HC3) Cybersecurity Threat Briefing…