← Vulnerability feed

Vulnerability record · CVE-2020-2038 · published 9 September 2020

CVE-2020-2038: PAN-OS management interface OS command injection

Paloaltonetworks · Pan Os

The PAN-OS management interface contains an OS command injection flaw (CWE-78) that lets an authenticated administrator run arbitrary OS commands as root. It affects PAN-OS 9.0 before 9.0.10, 9.1 before 9.1.4, and 10.0 before 10.0.1. Because the management interface is a high-value control plane, successful abuse gives full root control of the firewall.

7.2 CVSS 3.1 High EPSS 86% · top 0.3% CWE-78 · OS command injection
7.2CVSS 3.1 base score, v2 9.0
86%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References, 4 tagged exploit
17 Jun 2026Last modified by NVD

Description

An OS Command Injection vulnerability in the PAN-OS management interface that allows authenticated administrators to execute arbitrary OS commands with root privileges. This issue impacts: PAN-OS 9.0 versions earlier than 9.0.10; PAN-OS 9.1 versions earlier than 9.1.4; PAN-OS 10.0 versions earlier than 10.0.1.

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

high priorityRoot-level command execution on a security control plane with public exploit code and very high EPSS, though it requires authenticated admin access.

What it is

The PAN-OS management interface contains an OS command injection flaw (CWE-78) that lets an authenticated administrator run arbitrary OS commands as root. It affects PAN-OS 9.0 before 9.0.10, 9.1 before 9.1.4, and 10.0 before 10.0.1. Because the management interface is a high-value control plane, successful abuse gives full root control of the firewall.

Impact

An attacker with administrative access gains root-level command execution on the firewall, enabling full compromise of the device, its configuration, and potentially the network it protects.

Attack surface

Reached over the network through the PAN-OS management interface (AV:N) with no user interaction (UI:N), but it requires high privileges (PR:H), meaning a valid administrator account is needed.

Exploitation

Not listed in CISA KEV, but public exploit code exists per Packet Storm references and EPSS is very high (0.86086, 99.7th percentile), indicating elevated likelihood of exploitation.

What to do

  • Upgrade to PAN-OS 9.0.10, 9.1.4, 10.0.1 or later as the primary fix.
  • Restrict management interface access to trusted administrative networks and disable it on untrusted interfaces.
  • Enforce least privilege and strong authentication for administrator accounts, and audit who holds admin rights.
  • Monitor and alert on unexpected OS-level command execution or configuration changes on PAN-OS devices.

Detection

  • Review PAN-OS management interface logs for anomalous administrative sessions and command activity.
  • Alert on unexpected processes or shell activity on the firewall host.
  • Correlate admin logins with configuration changes or outbound connections from the management plane.
  • Hunt for known public exploit patterns against the management interface in web/proxy logs.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-2038 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2024-3400PAN-OS GlobalProtect command injection allows unauthenticated root code executionA command injection caused by arbitrary file creation in the GlobalProtect feature of Palo Alto Networks PAN-OS lets an unauthenticated attacker run …KEVEPSS 100%analysed10.0CVE-2020-2021PAN-OS SAML signature verification bypass allows authentication bypassPAN-OS fails to properly verify SAML signatures when SAML authentication is enabled and the 'Validate Identity Provider Certificate' option is unchec…KEVEPSS 4.4%analysed9.8CVE-2017-15944PAN-OS management interface input validation flaw allows remote code executionPAN-OS versions before 6.1.19, 7.0.x before 7.0.19, 7.1.x before 7.1.14, and 8.0.x before 8.0.6 contain an input validation and memory buffer overflo…KEVEPSS 98%analysed9.3CVE-2026-0300PAN-OS User-ID Authentication Portal buffer overflow allows root code executionA buffer overflow (out-of-bounds write, CWE-787) in the User-ID Authentication Portal (Captive Portal) service of Palo Alto Networks PAN-OS lets an u…KEVEPSS 32%analysed9.3CVE-2024-0012PAN-OS Management Web Interface Authentication BypassPAN-OS contains a missing authentication flaw (CWE-306) in the management web interface that lets an unauthenticated network attacker obtain PAN-OS a…KEVEPSS 100%analysed8.8CVE-2025-0108PAN-OS management web interface authentication bypassPAN-OS contains a missing-authentication flaw (CWE-306) in the management web interface that lets an unauthenticated attacker with network access inv…KEVEPSS 98%analysed8.7CVE-2024-3393PAN-OS DNS Security packet causes firewall reboot and maintenance modeA denial of service flaw in the DNS Security feature of Palo Alto Networks PAN-OS lets an unauthenticated attacker send a crafted packet through the …KEVEPSS 28%analysed8.6CVE-2022-0028PAN-OS URL filtering misconfiguration enables reflected TCP DoSA PAN-OS URL filtering policy misconfiguration allows a network-based attacker to use PA-Series, VM-Series and CN-Series firewalls to conduct reflect…KEVEPSS 2.4%analysed

Source: NIST National Vulnerability Database (record CVE-2020-2038), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.