CVE-2020-1975
Missing XML validation vulnerability in the PAN-OS web interface on Palo Alto Networks PAN-OS software allows authenticated users to inject arbitrary XML that results in privilege escalation. This issue affects PAN-OS 8.1 versions earlier than PAN-OS 8.1.12 and PAN-OS 9.0 versions earlier than PAN-OS 9.0.6. This issue does not affect PAN-OS 7.1, PAN-OS 8.0, or PAN-OS 9.1 or later versions.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 6.8
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H
- EPSS probability
- 0.38%
- CWE
- CWE-112
- Published
- 2020-02-12
- Last modified
- 2026-03-14
Affected products
- Palo Alto Networks PAN-OS
- Palo Alto Networks PAN-OS
- Palo Alto Networks PAN-OS
- Palo Alto Networks PAN-OS
Weakness type
Related vulnerabilities
- CVE-2026-1190 — Org.keycloak/keycloak-services: keycloak saml brokering: response delay due to unchecked notonorafter in subjectconfirmationdata
- CVE-2023-40310 — Missing XML Validation vulnerability in SAP PowerDesigner Client BPMN2 import
- CVE-2021-27780 — HCL BigFix Mobile / Modern Client Management is vulnerable to unauthenticated XML interaction
- CVE-2022-28213 — When a user access SOAP Web services in SAP BusinessObjects Business Intelligence Platform -...
- CVE-2021-1359 — Cisco Web Security Appliance Privilege Escalation Vulnerability
- CVE-2020-27282 — In Hamilton Medical AG,T1-Ventillator versions 2.2.3 and prior, an XML validation vulnerability in...