cvedb.io
CVE-2021-3033
CRITICAL · CVSS 9.1
EPSS exploitation probability: 0%
Published 2021-02-10T18:15:13.267 · Last modified 2026-06-17T04:04:35.830

Summary

An improper verification of cryptographic signature vulnerability exists in the Palo Alto Networks Prisma Cloud Compute console. This vulnerability enables an attacker to bypass signature validation during SAML authentication by logging in to the Prisma Cloud Compute console as any authorized user. This issue impacts: All versions of Prisma Cloud Compute 19.11, Prisma Cloud Compute 20.04, and Prisma Cloud Compute 20.09; Prisma Cloud Compute 20.12 before update 1. Prisma Cloud Compute SaaS version is not impacted by this vulnerability.

Affected products

paloaltonetworks — prisma_cloud

Does this affect you?

Add your gear to cvedb and we'll alert you only when paloaltonetworks ships something exploited.

Check my exposure →

References

This product uses data from the NVD API but is not endorsed or certified by the NVD. Informational only; not professional security advice.