← Vulnerability feed

Vulnerability record · CVE-2020-2039 · published 9 September 2020

CVE-2020-2039: PAN-OS management web interface uncontrolled resource consumption

Paloaltonetworks · Pan Os

The PAN-OS management web interface fails to delete temporary files uploaded during requests, allowing uncontrolled disk consumption. A remote unauthenticated attacker can repeatedly upload files until available disk space is exhausted, disrupting the management web interface. The flaw affects PAN-OS 8.1, 9.0, 9.1 and 10.0 branches below their fixed releases.

5.3 CVSS 3.1 Medium EPSS 46% · top 1.2% CWE-400 · Uncontrolled resource consumption
5.3CVSS 3.1 base score, v2 5.0
46%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

An uncontrolled resource consumption vulnerability in Palo Alto Networks PAN-OS allows for a remote unauthenticated user to upload temporary files through the management web interface that are not properly deleted after the request is finished. It is possible for an attacker to disrupt the availability of the management web interface by repeatedly uploading files until available disk space is exhausted. This issue impacts: PAN-OS 8.1 versions earlier than PAN-OS 8.1.16; PAN-OS 9.0 versions earlier than PAN-OS 9.0.10; PAN-OS 9.1 versions earlier than PAN-OS 9.1.4; PAN-OS 10.0 versions earlier than PAN-OS 10.0.1.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: high.

medium priorityUnauthenticated remote availability impact on the management plane with high EPSS, but no KEV listing, no known exploit, and only low availability impact per CVSS.

What it is

The PAN-OS management web interface fails to delete temporary files uploaded during requests, allowing uncontrolled disk consumption. A remote unauthenticated attacker can repeatedly upload files until available disk space is exhausted, disrupting the management web interface. The flaw affects PAN-OS 8.1, 9.0, 9.1 and 10.0 branches below their fixed releases.

Impact

An attacker can degrade or take down the management web interface by exhausting disk space, blocking administrators from managing the device. There is no confidentiality or integrity impact; only availability of the management plane is affected.

Attack surface

Reachable over the network through the PAN-OS management web interface, per the CVSS vector AV:N/PR:N/UI:N no authentication or user interaction is required. Exposure is limited to deployments where the management interface is network-reachable.

Exploitation

Not listed in CISA KEV and no public exploit tags appear in the references, which are vendor advisories only. EPSS is high (0.46383, 98.8th percentile), indicating elevated likelihood of attempted exploitation.

What to do

  • Upgrade to PAN-OS 8.1.16, 9.0.10, 9.1.4 or 10.0.1 or later as applicable to your branch.
  • Restrict management web interface access to trusted administrative networks and disable it on untrusted interfaces.
  • Monitor management-plane disk usage and alert on abnormal growth or repeated upload activity.
  • Apply rate limiting or access controls in front of the management interface where feasible.

Detection

  • Track management-plane disk utilization trends and alert on sustained or sudden increases.
  • Review management web interface access logs for repeated upload requests from single or unfamiliar sources.
  • Monitor for management interface unavailability or failed administrative logins coinciding with disk pressure.
  • Inspect temporary file directories on the firewall for accumulation of undeleted upload artifacts.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-2039 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2024-3400PAN-OS GlobalProtect command injection allows unauthenticated root code executionA command injection caused by arbitrary file creation in the GlobalProtect feature of Palo Alto Networks PAN-OS lets an unauthenticated attacker run …KEVEPSS 100%analysed10.0CVE-2020-2021PAN-OS SAML signature verification bypass allows authentication bypassPAN-OS fails to properly verify SAML signatures when SAML authentication is enabled and the 'Validate Identity Provider Certificate' option is unchec…KEVEPSS 4.4%analysed9.8CVE-2017-15944PAN-OS management interface input validation flaw allows remote code executionPAN-OS versions before 6.1.19, 7.0.x before 7.0.19, 7.1.x before 7.1.14, and 8.0.x before 8.0.6 contain an input validation and memory buffer overflo…KEVEPSS 98%analysed9.3CVE-2026-0300PAN-OS User-ID Authentication Portal buffer overflow allows root code executionA buffer overflow (out-of-bounds write, CWE-787) in the User-ID Authentication Portal (Captive Portal) service of Palo Alto Networks PAN-OS lets an u…KEVEPSS 32%analysed9.3CVE-2024-0012PAN-OS Management Web Interface Authentication BypassPAN-OS contains a missing authentication flaw (CWE-306) in the management web interface that lets an unauthenticated network attacker obtain PAN-OS a…KEVEPSS 100%analysed8.8CVE-2025-0108PAN-OS management web interface authentication bypassPAN-OS contains a missing-authentication flaw (CWE-306) in the management web interface that lets an unauthenticated attacker with network access inv…KEVEPSS 98%analysed8.7CVE-2024-3393PAN-OS DNS Security packet causes firewall reboot and maintenance modeA denial of service flaw in the DNS Security feature of Palo Alto Networks PAN-OS lets an unauthenticated attacker send a crafted packet through the …KEVEPSS 28%analysed8.6CVE-2022-0028PAN-OS URL filtering misconfiguration enables reflected TCP DoSA PAN-OS URL filtering policy misconfiguration allows a network-based attacker to use PA-Series, VM-Series and CN-Series firewalls to conduct reflect…KEVEPSS 2.4%analysed

Source: NIST National Vulnerability Database (record CVE-2020-2039), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.