CVE-2022-0028
KEVlargeReflected Amplification DoS in Palo Alto Networks PAN-OS Firewalls
CISA: Palo Alto Networks PAN-OS Reflected Amplification Denial-of-Service Vulnerability
CVE-2022-0028 is a reflected amplification denial-of-service (RDoS) flaw in Palo Alto Networks PAN-OS that lets a network-based attacker bounce amplified TCP traffic off vulnerable PA-Series, VM-Series, and CN-Series firewalls toward a target of the attacker's choosing. It is triggered when a URL filtering profile with one or more blocked categories is assigned to a source zone that contains an external-facing interface, a configuration the vendor describes as atypical and likely unintended. The attacker gains a denial-of-service vector that obscures their identity and implicates the firewall as the source of the attack, though the firewall's own confidentiality, integrity, and availability are not impacted. Affected organizations are those running PAN-OS firewalls with this URL filtering configuration on an internet-facing zone, while Panorama M-Series and virtual Panorama appliances are unaffected and Cloud NGFW and Prisma Access customers are already fixed. The issue is actively exploited: CISA added it to the Known Exploited Vulnerabilities Catalog on August 22, 2022, and news reports tie it to a DDoS attack on a service provider.
What to do: Apply the PAN-OS updates released by the week of August 15, 2022 per Palo Alto Networks' advisory for CVE-2022-0028. As an interim mitigation, audit URL filtering profiles and remove or reconfigure any profile with blocked categories assigned to a source zone that has an external-facing interface. Because this is a CISA KEV entry being actively exploited, affected organizations must patch per vendor instructions, while Cloud NGFW and Prisma Access customers require no action.
| Palo Alto Networks PAN-OS | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A PAN-OS URL filtering policy misconfiguration could allow a network-based attacker to conduct reflected and amplified TCP denial-of-service (RDoS) attacks. The DoS attack would appear to originate from a Palo Alto Networks PA-Series (hardware), VM-Series (virtual) and CN-Series (container) firewall against an attacker-specified target. To be misused by an external attacker, the firewall configuration must have a URL filtering profile with one or more blocked categories assigned to a source zone that has an external facing interface. This configuration is not typical for URL filtering and, if set, is likely unintended by the administrator. If exploited, this issue would not impact the confidentiality, integrity, or availability of our products. However, the resulting denial-of-service (DoS) attack may help obfuscate the identity of the attacker and implicate the firewall as the source of the attack. We have taken prompt action to address this issue in our PAN-OS software. All software updates for this issue are expected to be released no later than the week of August 15, 2022. This issue does not impact Panorama M-Series or Panorama virtual appliances. This issue has been resolved for all Cloud NGFW and Prisma Access customers and no additional action is required from them.
- Affected
- Palo Alto Networks PAN-OS
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- paloaltonetworks
- Products
- pan-os
- Weakness
- CWE-406
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H