Medium severity5.3NVD Advisory· Published May 13, 2020· Updated Jun 17, 2026
CVE-2020-1996
CVE-2020-1996
Description
A missing authorization vulnerability in the management server component of PAN-OS Panorama allows a remote unauthenticated user to inject messages into the management server ms.log file. This vulnerability can be leveraged to obfuscate an ongoing attack or fabricate log entries in the ms.log file This issue affects: All versions of PAN-OS 7.1 and 8.0; PAN-OS 8.1 versions earlier than 8.1.14; PAN-OS 9.0 versions earlier than 9.0.9.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3cpe:2.3:o:paloaltonetworks:pan-os:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:paloaltonetworks:pan-os:*:*:*:*:*:*:*:*range: >=7.1.0,<=7.1.26
- (no CPE)range: 7.1.*
Patches
Vulnerability mechanics
References
1- security.paloaltonetworks.com/CVE-2020-1996nvdVendor Advisory
News mentions
0No linked articles in our index yet.