Vulnerability record · CVE-2020-2039 · published 9 September 2020
CVE-2020-2039: PAN-OS management web interface uncontrolled resource consumption
Paloaltonetworks · Pan Os
The PAN-OS management web interface fails to delete temporary files uploaded during requests, allowing uncontrolled disk consumption. A remote unauthenticated attacker can repeatedly upload files until available disk space is exhausted, disrupting the management web interface. The flaw affects PAN-OS 8.1, 9.0, 9.1 and 10.0 branches below their fixed releases.
Description
An uncontrolled resource consumption vulnerability in Palo Alto Networks PAN-OS allows for a remote unauthenticated user to upload temporary files through the management web interface that are not properly deleted after the request is finished. It is possible for an attacker to disrupt the availability of the management web interface by repeatedly uploading files until available disk space is exhausted. This issue impacts: PAN-OS 8.1 versions earlier than PAN-OS 8.1.16; PAN-OS 9.0 versions earlier than PAN-OS 9.0.10; PAN-OS 9.1 versions earlier than PAN-OS 9.1.4; PAN-OS 10.0 versions earlier than PAN-OS 10.0.1.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Automated analysis
medium priorityUnauthenticated remote availability impact on the management plane with high EPSS, but no KEV listing, no known exploit, and only low availability impact per CVSS.
What it is
The PAN-OS management web interface fails to delete temporary files uploaded during requests, allowing uncontrolled disk consumption. A remote unauthenticated attacker can repeatedly upload files until available disk space is exhausted, disrupting the management web interface. The flaw affects PAN-OS 8.1, 9.0, 9.1 and 10.0 branches below their fixed releases.
Impact
An attacker can degrade or take down the management web interface by exhausting disk space, blocking administrators from managing the device. There is no confidentiality or integrity impact; only availability of the management plane is affected.
Attack surface
Reachable over the network through the PAN-OS management web interface, per the CVSS vector AV:N/PR:N/UI:N no authentication or user interaction is required. Exposure is limited to deployments where the management interface is network-reachable.
Exploitation
Not listed in CISA KEV and no public exploit tags appear in the references, which are vendor advisories only. EPSS is high (0.46383, 98.8th percentile), indicating elevated likelihood of attempted exploitation.
What to do
- Upgrade to PAN-OS 8.1.16, 9.0.10, 9.1.4 or 10.0.1 or later as applicable to your branch.
- Restrict management web interface access to trusted administrative networks and disable it on untrusted interfaces.
- Monitor management-plane disk usage and alert on abnormal growth or repeated upload activity.
- Apply rate limiting or access controls in front of the management interface where feasible.
Detection
- Track management-plane disk utilization trends and alert on sustained or sudden increases.
- Review management web interface access logs for repeated upload requests from single or unfamiliar sources.
- Monitor for management interface unavailability or failed administrative logins coinciding with disk pressure.
- Inspect temporary file directories on the firewall for accumulation of undeleted upload artifacts.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://security.paloaltonetworks.com/CVE-2020-2039 | Vendor Advisory |
| https://security.paloaltonetworks.com/CVE-2020-2039 | Vendor Advisory |
Track CVE-2020-2039 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2020-2039), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.