Learn about CVE-2020-1978, affecting VM-Series Plugin on Microsoft Azure, leading to inadvertent collection of credentials in Tech support files on HA configured VMs. Discover impact, mitigation steps, and prevention methods here.
VM-Series on Microsoft Azure: Inadvertent collection of credentials in Tech support files on HA configured VMs
Understanding CVE-2020-1978
What is CVE-2020-1978?
TechSupport files generated on Palo Alto Networks VM Series firewalls for Microsoft Azure platform with HA configuration inadvertently collect Azure dashboard service account credentials, potentially exposing confidential data.
The Impact of CVE-2020-1978
This vulnerability could allow a user with compromised credentials to manage all Azure resources under the subscription, impacting confidentiality and potentially availability. The issue affects specific versions of the VM-Series Plugin on Microsoft Azure.
Technical Details of CVE-2020-1978
Vulnerability Description
The vulnerability lies in unintentional credential collection in TechSupport files, affecting VM-Series Plugin versions prior to 1.0.9 for PAN-OS 9.0 on Microsoft Azure with HA configurations.
Affected Systems and Versions
Exploitation Mechanism
Mitigation and Prevention
Immediate Steps to Take
Long-Term Security Practices
Patching and Updates