Severity
High
Analysis Summary
When Security Assertion Markup Language (SAML) authentication is enabled and the ‘Validate Identity Provider Certificate’ option is disabled (unchecked), improper verification of signatures in PAN-OS SAML authentication enables an unauthenticated network-based attacker to access protected resources. The attacker must have network access to the vulnerable server to exploit this vulnerability.
Impact
Authentication bypass
Affected Vendors
Palo Alto
Affected Products
- PAN-OS 8.1 versions earlier than PAN-OS 8.1.15
- PAN-OS 9.1 versions earlier than PAN-OS 9.1.3
- PAN-OS 9.0 versions earlier than PAN-OS 9.0.9
- all versions of PAN-OS 8.0 (EOL)
Remediation
Refer to vendor’s advisory for the list of affected version and respective patches.

