LiveActive security incident?Get immediate response
CVE Record

CVE-2020-2035: PAN-OS: URL filtering policy is not enforced on TLS handshakes for decrypted HTTPS sessions

When SSL/TLS Forward Proxy Decryption mode has been configured to decrypt the web transactions, the PAN-OS URL filtering feature inspects the HTTP Host and URL path headers for policy enforcement on the decrypted HTTPS web transactions but does not consider Server Name Indication (SNI) field within the TLS Client Hello handshake. This allows a compromised host in a protected network to evade any security policy that uses URL filtering on a firewall configured with SSL Decryption in the Forward Proxy mode. A malicious actor can then use this technique to evade detection of communication on the TLS handshake phase between a compromised host and a remote malicious server. This technique does not increase the risk of a host being compromised in the network. It does not impact the confidentiality or availability of a firewall. This is considered to have a low impact on the integrity of the firewall because the firewall fails to enforce a policy on certain traffic that should have been blocked. This issue does not impact the URL filtering policy enforcement on clear text or encrypted web transactions. This technique can be used only after a malicious actor has compromised a host in the protected network and the TLS/SSL Decryption feature is enabled for the traffic that the attacker controls. Palo Alto Networks is not aware of any malware that uses this technique to exfiltrate data. This issue is applicable to all current versions of PAN-OS. This issue does not impact Panorama or WF-500 appliances.

LowCVSS 3Not KEV-listedUpdated
Glexia's TakeAutomated analysislow

Security readout for executives and security teams

Plain-English summary

This is a policy bypass issue in Palo Alto Networks PAN-OS URL filtering. It does not help an attacker break into the network or take down the firewall. It matters when an internal host is already compromised and outbound HTTPS traffic is decrypted by the firewall; certain TLS handshake traffic may avoid URL filtering enforcement.

Executive priority

Treat this as a low-severity control-gap remediation item. It should not interrupt critical operations, but teams relying on PAN-OS URL filtering for outbound containment should review exposure and vendor guidance, especially in environments with elevated endpoint compromise risk.

Technical view

PAN-OS URL filtering in SSL/TLS Forward Proxy Decryption inspects decrypted HTTP Host and URL path fields but does not consider SNI in the TLS Client Hello. A compromised protected host can use this gap to communicate during the TLS handshake phase despite URL filtering policy. Panorama and WF-500 are not affected.

Likely exposure

Exposure is limited to PAN-OS deployments using SSL/TLS Forward Proxy Decryption with URL filtering policy on attacker-controlled outbound traffic. The provided affected versions are PAN-OS 8.1.*, 9.0.*, 9.1.*, 10.0.*, and 10.1.*. Cleartext and normal encrypted web transaction enforcement are described as unaffected.

Exploitation context

The source bundle reports no KEV listing and Palo Alto Networks was not aware of malware using this technique for exfiltration. Exploitation requires a previously compromised internal host and traffic controlled by the attacker, so this is a post-compromise evasion issue rather than an initial access vector.

Researcher notes

The key constraint is SNI handling before decrypted HTTP fields are available. Evidence provided does not identify a patch level, live exploitation, or malware use. Avoid broad claims: this affects URL filtering enforcement under specific decryption conditions and has low firewall integrity impact.

Mitigation direction

  • Check Palo Alto Networks guidance for fixed PAN-OS releases or recommended mitigations.
  • Review reliance on URL filtering for decrypted outbound HTTPS enforcement.
  • Layer outbound controls beyond URL filtering for high-risk internal systems.
  • Monitor unusual TLS SNI or handshake-only communication from protected hosts.

Validation and detection

  • Inventory PAN-OS firewalls and versions in SSL Forward Proxy Decryption mode.
  • Confirm whether URL filtering policies govern decrypted outbound HTTPS traffic.
  • Review firewall logs for suspicious allowed TLS connections from compromised or high-risk hosts.
  • Verify Panorama and WF-500 are excluded from this specific exposure.
Prepared
Confidence
high
Sources
4

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cwe · low confidence lookup

CWE-20: Exact CWE lookup

Use the exact CWE identifier as the starting point before reviewing related ATT&CK behavior. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.

Open ATT&CK lookup
cve · low confidence lookup

CVE-2020-2035 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Low
CVSS
3 (3.1)
Known Exploited
No
Published

Vector: CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:N/I:L/A:N

Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

1CVSS vectors
0Timeline events
0ADP providers
3Source links

CVSS vector scores

1 official score

We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.

ScoreVersionSeverityVectorExploitImpactSource
3CVSS 3.1LowCVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:N/I:L/A:N1.31.4Primary CVE score

Vulnerability scoring details

Base CVSS 3.1 score

3Low
CVSS 3.1 vector shape for CVE-2020-2035Attack VectorAttack ComplexityPrivileges RequiredUser InteractionScopeConfidentiality ImpactIntegrity ImpactAvailability Impact

Vector: CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:N/I:L/A:N

Attack Vector
NetworkAdjacentLocalPhysical
Attack Complexity
LowHigh
Privileges Required
NoneLowHigh
User Interaction
NoneRequired
Scope
ChangedUnchanged
Confidentiality Impact
HighLowNone
Integrity Impact
HighLowNone
Availability Impact
HighLowNone

Source materials

Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
Palo Alto NetworksPAN-OS8.1.*, 9.0.*, 9.1.*, 10.0.*, 10.1.*Listed
Weakness

CWE details

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.