CISA Adds Palo Alto Networks' PAN
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2022-0028 | Reflected Amplification DoS in Palo Alto Networks PAN-OS Firewalls CVE-2022-0028 is a reflected amplification denial-of-service (RDoS) flaw in Palo Alto Networks PAN-OS that lets a network-based attacker bounce amplified TCP traffic off vulnerable PA-Series, VM-Series, and CN-Series firewalls toward a target of the attacker's choosing. It is triggered when a URL filtering profile with one or more blocked categories is assigned to a source zone that contains an external-facing interface, a configuration the vendor describes as atypical and likely unintended. The attacker gains a denial-of-service vector that obscures their identity and implicates the firewall as the source of the attack, though the firewall's own confidentiality, integrity, and availability are not impacted. Affected organizations are those running PAN-OS firewalls with this URL filtering configuration on an internet-facing zone, while Panorama M-Series and virtual Panorama appliances are unaffected and Cloud NGFW and Prisma Access customers are already fixed. The issue is actively exploited: CISA added it to the Known Exploited Vulnerabilities Catalog on August 22, 2022, and news reports tie it to a DDoS attack on a service provider. Do: Apply the PAN-OS updates released by the week of August 15, 2022 per Palo Alto Networks' advisory for CVE-2022-0028. As an interim mitigation, audit URL filtering profiles and remove or reconfigure any profile with blocked categories assigned to a source zone that has an external-facing interface. Because this is a CISA KEV entry being actively exploited, affected organizations must patch per vendor instructions, while Cloud NGFW and Prisma Access customers require no action. | 8.6 | 2% | KEV |
| largetens of thousands of internet-exposed PAN-OS firewalls, of which only a subset with the atypical URL filtering configuration is actually exploitable |
Full article303 words · extracted from infosecurity-magazine.com · click to collapse
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a security flaw affecting Palo Alto Networks PAN-OS to its Known Exploited Vulnerabilities Catalog on Monday.
Tracked CVE-2022-0028, the vulnerability has a CVSS of 8.6 and is based on the misconfiguration of the PAN-OS URL filtering policy, which could allow a network-based unauthenticated attacker to perform mirrored and amplified TCP denial-of-service (DoS) attacks.
“To be misused by an external attacker, the firewall configuration must have a URL filtering profile with one or more blocked categories assigned to a security rule with a source zone that has an external facing network interface,” Palo Alto Networks said earlier this month.
“This configuration is not typical for URL filtering and, if set, is likely unintended by the administrator.”
The company also confirmed that if exploited, this issue would not impact the confidentiality, integrity, or availability of its products.
“However, the resulting denial-of-service (DoS) attack may help obfuscate the identity of the attacker and implicate the firewall as the source of the attack,” Palo Alto Networks wrote.
The flaw has now been patched by the company, but before issuing a patch, Palo Alto Networks confirmed an attempted reflected DoS (RDoS) attack was identified by a service provider.
“This attempted attack took advantage of susceptible firewalls from multiple vendors, including Palo Alto Networks. We immediately started to root cause and remediate this issue.”
To prevent DoS attacks resulting from this issue from various sources, the company suggested system administrators configure their Palo Alto Networks firewalls by enabling one of the two-zone protection mitigations on all security zones with an assigned security policy that includes a URL filtering profile.
The news of the vulnerability being patched and added to CISA’s catalog comes weeks after Palo Alto Networks’ security researchers spotted a new Ursula campaign against DropBox and Google Drive accounts.
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.infosecurity-magazine.com/news/cisa-palo-alto-networks-pan-os/