Palo Alto Networks Vulnerability – CVE-2020-2021

On June 29, 2020 Palo Alto Networks published a notice about a critical vulnerability affecting their devices. The vulnerability, which is listed as an issue affecting the way SAML (Security Assertion Markup Language) authentication happens, can be exploited by remote attackers to gain access to the device. Dissecting this vulnerability, Palo Alto states that

Information Leakage and Improper Error Handling vulnerability found in Axcient / eFolder Synced Tool

This vulnerability was responsibly disclosed to Axcient/Anchor on November 4, 2019. Affected versions: > During a penetration test we came across a file sharing application called SynedTool. When performing some of the more simpler tests we identified that this application is vulnerable to an Information Leakage and Improper Error Handling vulnerability. The application allows

2020-07-13T12:54:45-04:00January 8th, 2020|Vulnerability, Vulnerability Disclosure|
