CISA KEV · Known exploitedHigh

CVE-2022-0028

Palo Alto Networks PAN-OS

A PAN-OS URL filtering policy misconfiguration could allow a network-based attacker to conduct reflected and amplified TCP denial-of-service (RDoS) attacks. The DoS attack would appear to originate from a Palo Alto Networks PA-Series (hardware), VM-Series (virtual) and CN-Series (container) firewall against an attacker-specified target. To be misused by an external attacker, the firewall configuration must have a URL filtering profile with one or more blocked categories assigned to a source zone that has an external facing interface. This configuration is not typical for URL filtering and,...

CVSS
8.6
EPSS
2.13%
80.1% percentile
CISA KEV
Listed
Published
2022.08.11
PRIORITY ASSESSMENT

Immediate review

CISA has listed this vulnerability in the Known Exploited Vulnerabilities catalog.

Known exploitationConfirmed by CISA KEV
Exploit probability2.13%
Technical severityCVSS 8.6

Vulnerability overview

A PAN-OS URL filtering policy misconfiguration could allow a network-based attacker to conduct reflected and amplified TCP denial-of-service (RDoS) attacks. The DoS attack would appear to originate from a Palo Alto Networks PA-Series (hardware), VM-Series (virtual) and CN-Series (container) firewall against an attacker-specified target. To be misused by an external attacker, the firewall configuration must have a URL filtering profile with one or more blocked categories assigned to a source zone that has an external facing interface. This configuration is not typical for URL filtering and,...

Affected product and versions

Product
Palo Alto Networks PAN-OS
Affected versions
8.1, 9.0, 9.1, 10.0, 10.1, 10.2, 8.1.0, 9.0.0, 9.1.0, 10.0.0, 10.1.0, 10.2.0, >= 8.1.0 < 8.1.23, >= 9.0.0 < 9.0.16, >= 9.1.0 < 9.1.14, >= 10.0.0 < 10.0.11, >= 10.1.0 < 10.1.6, >= 10.2.0 < 10.2.2, 8.1.23, 9.0.16
Fixed versions
8.1.23, 9.0.16, 9.1.14, 10.0.11, 10.1.6, 10.2.2

Recommended response sequence

Confirm exposure before applying a vendor-supported change.

Full remediation guide
CISA required action

Apply updates per vendor instructions.

Due date: 2022.09.12
  1. 1
    Identify

    Confirm that Palo Alto Networks PAN-OS and an affected version are present.

  2. 2
    Prioritize

    Combine exploitation signals with asset exposure and business criticality.

  3. 3
    Remediate

    Follow the vendor advisory or supported update path and preserve rollback options.

  4. 4
    Verify

    Recheck the version, service health, access paths, and relevant logs.

Technical data

CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
CWE
CWE-406, CWE-940
KEV added
2022.08.22
Ransomware use
미확인