Palo Alto has released security updates to address a vulnerability in Palo Alto Networks PAN-OS. The remote attacker could exploit this vulnerability to take control of the affected system.
Palo Alto Networks PAN-OS is vulnerable to a denial of service, caused by a misconfiguration flaw in the URL filtering policy. The remote attacker could exploit this vulnerability by sending a specially-crafted request to conduct reflected and amplified TCP denial-of-service (RDoS) attacks.
The mentioned DoS attack would appear to originate from a Palo Alto Networks PASeries (hardware), VM-Series (virtual), and CN-Series (container) firewall against an attacker-specified target.
Palo Alto Networks PAN-OS denial of service (CVE-2022-0028):
It should be highlighted that Palo Alto is aware of a specifically crafted proof of concept (POC) that reduces the effectiveness of the Cortex XDR agent Anti- Ransomware endpoint protection module. This flaw affected versions earlier than (CU-610) therefore Palo Alto recommends deploying the update to (CU-610) content update and later.
CVE-2022-0028
The enterprise should deploy this patch as soon as the testing phase is completed.
Palo Alto Networks Security Advisories
Cookie | Duration | Description |
---|---|---|
cookielawinfo-checkbox-analytics | 11 months | This cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Analytics". |
cookielawinfo-checkbox-functional | 11 months | The cookie is set by GDPR cookie consent to record the user consent for the cookies in the category "Functional". |
cookielawinfo-checkbox-necessary | 11 months | This cookie is set by GDPR Cookie Consent plugin. The cookies is used to store the user consent for the cookies in the category "Necessary". |
cookielawinfo-checkbox-others | 11 months | This cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Other. |
cookielawinfo-checkbox-performance | 11 months | This cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Performance". |
viewed_cookie_policy | 11 months | The cookie is set by the GDPR Cookie Consent plugin and is used to store whether or not user has consented to the use of cookies. It does not store any personal data. |