Threat advisory · Cross-sector

Palo Alto PAN-OS Vulnerability CVE-2022-0028

A misconfigured URL filtering policy in PAN-OS, CVE-2022-0028, lets attackers use firewalls for reflected denial-of-service attacks; a patch is available.

Technical Detail and Additional Info

What is the Threat?

Within PAN-OS, the URL filtering policy was misconfigured which allows an attacker to perform reflected and amplified TCP DoS attacks. This technique often exploits TCP non-compliance in middleboxes which can be used to reflect an attacker’s request onto their intended target. Once exploited, attackers can perform DoS attacks, giving an attacker the ability to flood a target with requests. This will ultimately crash the machine, making it inaccessible to its intended users.

Why Is It Noteworthy?

PAN-OS is a proprietary operating system of Palo Alto, and is used in over 150 countries. This vulnerability affects devices running various versions of PAN-OS 8.1, 9.0, 9.1, 10.0, 10.1, and 10.2 specifically. For CVE-2022-0028, it received a Common Vulnerability Scoring System (CVSS) score of an 8.6. This is considered a high score and recommends immediate action.

What Is The Exposure Or Risk?

When exploited, a DoS attack can be performed. According to Palo Alto’s advisory published recently, “If exploited, this issue would not impact the confidentiality, integrity, or availability of our products. However, the resulting DoS attack may help obfuscate the identity of the attacker and implicate the firewall as the source of the attack.” The resulting DoS attack can potentially result in a loss of availability for the attacker-specified target if that target lacks sufficient DoS protection. A way to notice if your devices have been attacked is if there is an abnormal increase in URL Filtering Logs with a block action that has many retries by the same set of external source IP addresses.

What Are The Recommendations?

happier IT recommends the following actions to mitigate this vulnerability on your Palo Alto products:

  • Apply the latest security update to affected devices.
  • If a DoS attack were to take place, consider the following workaround Packet-based attack protection including both (Packet Based Attack Protection > TCP Drop > TCP SYN with Data) and (Packet Based Attack Protection > TCP Drop > Strip TCP Options > TCP Fast Open).
  • Also consider: Flood protection (Flood Protection > SYN > Action > SYN Cookie) with an activation threshold of 0 connections (It is not necessary nor advantageous to apply both the attack and flood protections).

References

For more in-depth information about the recommendations, please visit the following links:

More from the feed

Other incidents we've written up.

Want to know what this would look like for you?

A 30-minute call. No slides, no audit fee, no obligation. We ask what is breaking and tell you honestly whether we are the right fit.