Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2020-1977— Expedition Migration Tool: Insufficient Cross Site Request Forgery protection.

CVSS 7.5 · High EPSS 0.19% · P41
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2020-1977

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Expedition Migration Tool: Insufficient Cross Site Request Forgery protection.
Source: NVD (National Vulnerability Database)
Vulnerability Description
Insufficient Cross-Site Request Forgery (XSRF) protection on Expedition Migration Tool allows remote unauthenticated attackers to hijack the authentication of administrators and to perform actions on the Expedition Migration Tool. This issue affects Expedition Migration Tool 1.1.51 and earlier versions.
Source: NVD (National Vulnerability Database)
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Source: NVD (National Vulnerability Database)
Vulnerability Type
跨站请求伪造(CSRF)
Source: NVD (National Vulnerability Database)
Vulnerability Title
Palo Alto Networks Expedition Migration Tool 跨站请求伪造漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Palo Alto Networks Expedition Migration Tool是美国Palo Alto Networks公司的一款安全策略(配置)迁移工具。 Palo Alto Networks Expedition Migration Tool 1.1.51及之前版本中存在跨站请求伪造漏洞,该漏洞源于没有充分地进行跨站请求伪造保护。远程攻击者可利用该漏洞执行管理员操作。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
Palo Alto NetworksExpedition 1.1 ~ 1.1.51 -

II. Public POCs for CVE-2020-1977

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2020-1977

登录查看更多情报信息。

Same Patch Batch · Palo Alto Networks · 2020-02-12 · 3 CVEs total

CVE-2020-19756.8 MEDIUMMissing XML Validation in PAN-OS Web Interface
CVE-2020-19764.7 MEDIUMGlobalProtect on MacOS: Local denial-of-service (DoS) vulnerability.

IV. Related Vulnerabilities

V. Comments for CVE-2020-1977

No comments yet


Leave a comment