Software running Palo Alto Networks’ firewalls is under attack, prompting U.S. Cybersecurity and Infrastructure Security Agency (CISA) to issue a warning to public and federal IT security teams to apply available fixes. Federal agencies urged to patch the bug by September 9. Earlier this month, Palo Alto Networks issued a fix for the high-severity bug (CVE-2022-0028) that it says adversaries attempted to exploit. The flaw could be used by remote hackers to carry out reflected and amplified denial-of-service (DoS) attacks without having to authenticate targeted systems. Palo Alto Networks maintains the flaw can only be exploited on a limited number of systems, under certain conditions and that the vulnerable systems are not part of a common firewall configuration. Any additional attacks exploiting the bug have either not occurred or been publicly reported. Affected products include those running the PAN-OS firewall software include PA-Series, VM-Series and CN-Series devices. PAN-OS versions vulnerable to attack, with patches available, include PAN-OS prior to 10.2.2-h2, PAN-OS prior to 10.1.6-h6, PAN-OS prior to 10.0.11-h1, PAN-OS prior to 9.1.14-h4, PAN-OS prior to 9.0.16-h3 and PAN-OS prior to 8.1.23-h1. According to Palo Alto Networks advisory; “A PAN-OS URL filtering policy misconfiguration could allow a network-based attacker to conduct reflected and amplified TCP denial-of-service (RDoS) attacks. The DoS attack would appear to originate from a Palo Alto Networks PA-Serie...
Firewall Bug Under Active Attack Triggers CISA Warning
Threatpost
·Threatpost
·Published Aug 23, 2022
·Updated
Affected Software
4 affected components
Palo Alto Networks PAN-OS<10.2.2-h2, <10.1.6-h6, <10.0.11-h1, <9.1.14-h4, <9.0.16-h3, <8.1.23-h1
Palo Alto Networks PA-Series<10.2.2-h2, <10.1.6-h6, <10.0.11-h1, <9.1.14-h4, <9.0.16-h3, <8.1.23-h1
Palo Alto Networks VM-Series<10.2.2-h2, <10.1.6-h6, <10.0.11-h1, <9.1.14-h4, <9.0.16-h3, <8.1.23-h1
Palo Alto Networks CN-Series<10.2.2-h2, <10.1.6-h6, <10.0.11-h1, <9.1.14-h4, <9.0.16-h3, <8.1.23-h1
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses a security vulnerability in Palo Alto Networks’ firewalls that is currently being exploited.
2
What organization issued a warning about the firewall bug?
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) issued the warning.
3
Which software products are affected by the bug?
The affected products include Palo Alto Networks PAN-OS, PA-Series, VM-Series, and CN-Series.
4
What action has CISA recommended for federal agencies?
CISA recommends that federal agencies apply available fixes by September 9.
5
What type of threat is currently posed by the firewall bug?
The threat posed is an active attack that exploits the vulnerability in the firewall software.