Checking CVE-2020-2040 it says "Until PAN-OS software is upgraded to a fixed version, enabling signatures in content update version 8317 will block attacks against CVE-2020-2040.", and I'm not sure what does "enabling signatures in content update version 8317" mean and can't find anything online about it.
In content version 8317 we released 4 new vulnerability signatures (UTIDs 59270, 59255, 59259, 59267) to provide coverage against CVE-2020-2040; so until you upgrade PAN-OS, you can enforce the traffic with a security policy with a Vulnerability Protection Profile and this will help to deter any potential attempt of exploitation of this vulnerability.
Enable the No auto-restart for scheduled Automatic Updates installations parameter. Bypass Approval permission to this role and adding the relevant content sets. Windows OS Major Version > 6.0 and Tanium Client Version >= 7.2.314.3211 and Repo GPG Check to confirm authenticity by verifying GPG signatures.
Always review Content Release Notes for the list of newly-identified and modified application and threat signatures that the content release introduces. Content Release Notes also describe how the update might impact existing security policy enforcement and provides recommendations on how you can modify your security policy to best leverage what’s new.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!