CVE-2020-25844: Panorama Nhiservisignadapter

Critical severity, CVSS 9.8. EPSS: 2% chance of exploitation in the next 30 days.

The digest generation function of NHIServiSignAdapter has not been verified for parameter’s length, which leads to a stack overflow loophole. Remote attackers can use the leak to execute code without privilege.

Affected products

  • Panorama Nhiservisignadapter: version 1.0.20.0218 only

Published 2020-12-31. Last modified 2026-06-17.