CVE-2020-25843: Panorama Nhiservisignadapter

Critical severity, CVSS 9.8. EPSS: 2% chance of exploitation in the next 30 days.

NHIServiSignAdapter fails to verify the length of digital credential files’ path which leads to a heap overflow loophole. Remote attackers can use the leak to execute code without privilege.

Affected products

  • Panorama Nhiservisignadapter: version 1.0.20.0218 only

Published 2020-12-31. Last modified 2026-06-17.