CISA Warning Against Active Exploitation of Palo Alto Networks’ PAN-OS Vulnerability

This image is about CISA's warning regarding the active exploitation of a Palo Alto Networks PAN-OS vulnerability.

This blog is about CISA’s warning regarding the active exploitation of a Palo Alto Networks PAN-OS vulnerability.

PAN-OS vulnerability.

CISA added Palo Alto Networks PAN-OS to its Catalog of Known Exploited Vulnerabilities based on evidence of active exploitation

This critical vulnerability is tracked with code CVE-2022-0028 (CVSS: 8.6 High). The vulnerability is the misconfiguration of a URL filtering policy. Misconfiguration of the PAN-OS URL filtering policy could allow a network-based attacker to perform mirrored and amplified TCP denial-of-service (RDoS) attacks.

Palo Alto Networks said that

exploiting this issue will not affect the confidentiality, integrity, or availability of its products.

“However, the resulting denial of service (DoS) attack can help disguise the identity of the attacker and expose the firewall as the source of the attack,” Palto Alto Networks added.

Customers are encouraged to apply patches for affected products to mitigate potential threats.

References:

https://nvd.nist.gov/vuln/detail/CVE-2022-0028

https://www.cisa.gov/known-exploited-vulnerabilities-catalog

https://security.paloaltonetworks.com/CVE-2022-0028

More posts

This image is about multiple Nginx vulnerabilities.
This image is about multiple Microsoft IIS vulnerabilities.
This image is about SMTP open mail relay vulnerability.
SSL Expire" means an SSL certificate has expired, causing security warnings for site visitors.
What is Server Header Information Disclosure?
advanced divider

Share this article

Found it interesting? Don’t hesitate to share it to wow your friends or colleagues
advanced divider
Subscribe to our blog newsletter to follow the latest posts