Vulnerability record · CVE-2020-2038 · published 9 September 2020
CVE-2020-2038: PAN-OS management interface OS command injection
Paloaltonetworks · Pan Os
The PAN-OS management interface contains an OS command injection flaw (CWE-78) that lets an authenticated administrator run arbitrary OS commands as root. It affects PAN-OS 9.0 before 9.0.10, 9.1 before 9.1.4, and 10.0 before 10.0.1. Because the management interface is a high-value control plane, successful abuse gives full root control of the firewall.
Description
An OS Command Injection vulnerability in the PAN-OS management interface that allows authenticated administrators to execute arbitrary OS commands with root privileges. This issue impacts: PAN-OS 9.0 versions earlier than 9.0.10; PAN-OS 9.1 versions earlier than 9.1.4; PAN-OS 10.0 versions earlier than 10.0.1.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityRoot-level command execution on a security control plane with public exploit code and very high EPSS, though it requires authenticated admin access.
What it is
The PAN-OS management interface contains an OS command injection flaw (CWE-78) that lets an authenticated administrator run arbitrary OS commands as root. It affects PAN-OS 9.0 before 9.0.10, 9.1 before 9.1.4, and 10.0 before 10.0.1. Because the management interface is a high-value control plane, successful abuse gives full root control of the firewall.
Impact
An attacker with administrative access gains root-level command execution on the firewall, enabling full compromise of the device, its configuration, and potentially the network it protects.
Attack surface
Reached over the network through the PAN-OS management interface (AV:N) with no user interaction (UI:N), but it requires high privileges (PR:H), meaning a valid administrator account is needed.
Exploitation
Not listed in CISA KEV, but public exploit code exists per Packet Storm references and EPSS is very high (0.86086, 99.7th percentile), indicating elevated likelihood of exploitation.
What to do
- Upgrade to PAN-OS 9.0.10, 9.1.4, 10.0.1 or later as the primary fix.
- Restrict management interface access to trusted administrative networks and disable it on untrusted interfaces.
- Enforce least privilege and strong authentication for administrator accounts, and audit who holds admin rights.
- Monitor and alert on unexpected OS-level command execution or configuration changes on PAN-OS devices.
Detection
- Review PAN-OS management interface logs for anomalous administrative sessions and command activity.
- Alert on unexpected processes or shell activity on the firewall host.
- Correlate admin logins with configuration changes or outbound connections from the management plane.
- Hunt for known public exploit patterns against the management interface in web/proxy logs.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://packetstormsecurity.com/files/168008/PAN-OS-10.0-Remote-Code-Execution.html | ExploitThird Party AdvisoryVDB Entry |
| http://packetstormsecurity.com/files/168408/Palo-Alto-Networks-Authenticated-Remote-Code-Execution.html | ExploitThird Party AdvisoryVDB Entry |
| https://security.paloaltonetworks.com/CVE-2020-2038 | Vendor Advisory |
| http://packetstormsecurity.com/files/168008/PAN-OS-10.0-Remote-Code-Execution.html | ExploitThird Party AdvisoryVDB Entry |
| http://packetstormsecurity.com/files/168408/Palo-Alto-Networks-Authenticated-Remote-Code-Execution.html | ExploitThird Party AdvisoryVDB Entry |
| https://security.paloaltonetworks.com/CVE-2020-2038 | Vendor Advisory |
Track CVE-2020-2038 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2020-2038), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.