CVE-2020-2021: PAN-OS SAML Security Bypass
ID: 50d0769b-0105-53bf-a0ce-e280ba7cbc4a
STIX ID: report--50d0769b-0105-53bf-a0ce-e280ba7cbc4a
Feed Name: TrustedSec blog
Threat Score
**Executive Summary:** The report details CVE-2020-2021, a critical SAML signature verification bypass in Palo Alto PAN-OS that can allow unauthenticated access—especially against GlobalProtect VPNs—when SAML auth is enabled and the "Validate Identity Provider Certificate" option is disabled; it lists affected versions, mitigation (upgrade/Palo Alto guidance), monitoring logs for potential compromise, and notes no public proof-of-concept or confirmed exploitation to date.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
