Palo Alto Security Updates – 13 October 2022

Palo Alto has released a security update to address a vulnerability in Palo Alto Networks PAN-OS. The remote attacker could exploit this vulnerability to take control of the affected system.

Palo Alto Networks PAN-OS is vulnerable to authentication bypass vulnerability in the PAN-OS 8.1 web interface that could allow the network-based attacker with specific knowledge of the target firewall or Panorama appliance to impersonate an existing PAN-OS administrator and perform privileged actions.

PAN-OS: Authentication Bypass in Web Interface (CVE-2022-0030):

  • CVSS: 8.1
  • Attack Vector: Network
  • Attack Complexity: High
  • Privileges Required: None
  • User Interaction: None
  • Consequences: Bypass Security
Vulnerabilities

CVE-2022-0030

Mitigations

The enterprise should deploy this patch as soon as the testing phase is completed.

Palo Alto Networks Security Advisories

References