Rewterz
Rewterz Threat Advisory – Multiple VMware vRealize Operations Vulnerabilities
August 10, 2022
Rewterz
Rewterz Threat Alert – APT32 Ocean Lotus – Active IOCs
August 11, 2022

Rewterz Threat Advisory – CVE-2022-0028 – Palo Alto PAN-OS: Reflected Amplification Vulnerability

Severity

High

Analysis Summary

CVE-2022-0028
A PAN-OS URL filtering policy misconfiguration could allow a network-based attacker to conduct reflected and amplified TCP denial-of-service (RDoS) attacks. The DoS attack would appear to originate from a Palo Alto Networks PA-Series (hardware), VM-Series (virtual) and CN-Series (container) firewall against an attacker-specified target.

Impact

  • Denial of Service

Indicators Of Compromise

CVE

  • CVE-2022-0028

Affected Vendors

Palo Alto

Affected Products

  • Cloud NGFW
  • PAN-OS 10.2
  • PAN-OS 10.1
  • PAN-OS 10.0
  • PAN-OS 9.1
  • PAN-OS 9.0
  • PAN-OS 8.1
  • Prisma Access 3.1
  • Prisma Access 3.0
  • Prisma Access 2.2
  • Prisma Access 2.1

Remediation

Refer to Palo Alto Security Advisory for patch, upgrade or suggested workaround information.
Palo Alto Security Advisory