CISA Warns of Active Exploitation of Palo Alto Networks' PAN
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2022-0028 | Reflected Amplification DoS in Palo Alto Networks PAN-OS Firewalls CVE-2022-0028 is a reflected amplification denial-of-service (RDoS) flaw in Palo Alto Networks PAN-OS that lets a network-based attacker bounce amplified TCP traffic off vulnerable PA-Series, VM-Series, and CN-Series firewalls toward a target of the attacker's choosing. It is triggered when a URL filtering profile with one or more blocked categories is assigned to a source zone that contains an external-facing interface, a configuration the vendor describes as atypical and likely unintended. The attacker gains a denial-of-service vector that obscures their identity and implicates the firewall as the source of the attack, though the firewall's own confidentiality, integrity, and availability are not impacted. Affected organizations are those running PAN-OS firewalls with this URL filtering configuration on an internet-facing zone, while Panorama M-Series and virtual Panorama appliances are unaffected and Cloud NGFW and Prisma Access customers are already fixed. The issue is actively exploited: CISA added it to the Known Exploited Vulnerabilities Catalog on August 22, 2022, and news reports tie it to a DDoS attack on a service provider. Do: Apply the PAN-OS updates released by the week of August 15, 2022 per Palo Alto Networks' advisory for CVE-2022-0028. As an interim mitigation, audit URL filtering profiles and remove or reconfigure any profile with blocked categories assigned to a source zone that has an external-facing interface. Because this is a CISA KEV entry being actively exploited, affected organizations must patch per vendor instructions, while Cloud NGFW and Prisma Access customers require no action. | 8.6 | 2% | KEV |
| largetens of thousands of internet-exposed PAN-OS firewalls, of which only a subset with the atypical URL filtering configuration is actually exploitable |
Full article260 words · extracted from thehackernews.com · click to collapse
Ravie LakshmananAug 23, 2022
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a security flaw impacting Palo Alto Networks PAN-OS to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation.
The high-severity vulnerability, tracked as CVE-2022-0028 (CVSS score: 8.6), is a URL filtering policy misconfiguration that could allow an unauthenticated, remote attacker to carry out reflected and amplified TCP denial-of-service (DoS) attacks.
"If exploited, this issue would not impact the confidentiality, integrity, or availability of our products," Palo Alto Networks said in an alert. "However, the resulting denial-of-service (DoS) attack may help obfuscate the identity of the attacker and implicate the firewall as the source of the attack.
The weakness impacts the following product versions and has been addressed as part of updates released this month -
- PAN-OS 10.2 (version < 10.2.2-h2)
- PAN-OS 10.1 (version < 10.1.6-h6)
- PAN-OS 10.0 (version < 10.0.11-h1)
- PAN-OS 9.1 (version < 9.1.14-h4)
- PAN-OS 9.0 (version < 9.0.16-h3), and
- PAN-OS 8.1 (version < 8.1.23-h1)
The networking equipment maker said it discovered the vulnerability after being notified that susceptible firewall appliances from different vendors, including Palo Alto Networks, were being used as part of an attempted reflected denial-of-service (RDoS) attack.
In light of active exploitation, customers of affected products are advised to apply the relevant patches to mitigate potential threats. Federal Civilian Executive Branch (FCEB) agencies are mandated to update to the latest version by September 12, 2022.
Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.
Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2022/08/cisa-warns-of-active-exploitation-of.html