CVE-2020-8597 is it applicable for Palo alto ?

We have received a Critical Security Advisory related to Buffer Overflow Vulnerability in Point-to-Point Protocol Daemon (pppd).
 is applicable to our PaloAlto and Panorama Firewall devices.?

Risk Advisory No CVE-2020-8597
Advisory Name Buffer Overflow Vulnerability in Point-to-Point Protocol Daemon (pppd)
Severity Critical
Action Required Immediate
Summary CVE-2020-8597
CVE A new buffer overflow vulnerability has been discovered in pppd (Point to Point Protocol Daemon) versions 2.4.2 through 2.4.8. An unauthenticated remote attacker could cause memory corruption in the pppd process, which may allow for arbitrary code execution. System administrators are encouraged to update pppd software with the latest available patches in order to prevent vulnerability exploitation.
Affected Products Buffer Overflow Vulnerability in Point-to-Point Protocol Daemon (pppd) versions 2.4.2 through 2.4.8 are vulnerable
to CVE-2020-8597. This package is included in software products from different vendors. Please find below the list of confirmed affected vendors:
• Cisco
• Debian GNU/Linux
• Fedora Project
• NetBSD
• OpenWRT
• Red Hat
• Sierra Wireless
• SUSE Linux
• Synology
• Ubuntu
Recommendations It is recommended to update the pppd package with the latest available patches provided by each vendor. An authenticated attacker may still be able to exploit the vulnerability even if EAP is not enabled by sending unsolicited EAP packets to trigger
the buffer overflow. If the package has been compiled from source, the latest software can be obtained
from the pppd repository in Github:
For those using the lwIP (lightweight IP) package compiled from source with EAP
enabled at compile time, the latest version is also available on Github:



Re: CVE-2020-8597 is it applicable for Palo alto ?

With the release of PAN-OS 9.0.1 Palo Alto Networks has a new Security Advisory site.  Please see for details.


It does not appear that Palo Alto Networks devices are vulnerable to this specific advisory.

I searched that site and did not find it. 


I would recommend that you search that site for all CVE's or visit:



