<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Palo Alto Reponse to CVE-2023-48795 in Custom Signatures</title>
    <link>https://live.paloaltonetworks.com/t5/custom-signatures/palo-alto-reponse-to-cve-2023-48795/m-p/572559#M492</link>
    <description>&lt;P&gt;Thanks for the update.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 10 Jan 2024 14:10:11 GMT</pubDate>
    <dc:creator>Usama-Ahmed</dc:creator>
    <dc:date>2024-01-10T14:10:11Z</dc:date>
    <item>
      <title>Palo Alto Reponse to CVE-2023-48795</title>
      <link>https://live.paloaltonetworks.com/t5/custom-signatures/palo-alto-reponse-to-cve-2023-48795/m-p/571858#M489</link>
      <description>&lt;P&gt;Hi all! I am curious whether&amp;nbsp; anyone knows if &lt;SPAN&gt;Palo Alto has any made any response to&amp;nbsp;CVE-2023-48795? This vulnerabilities has been out for awhile and other vendors have already provided some types of response however, I am not able to find one from Palo Alto.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;FYI, &lt;/SPAN&gt;CVE-2023-48795 also known as Terrapin which is found in the SSH protocol and affects SSH channel integrity, details refer to link below:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://urldefense.com/v3/__https:/cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-48795__;!!KDf9ebxpXGLC!HtQHluwjyktmn2ar_VItyjiRnxbhVY742T6ImLGovIgC7cDngZCthOA0wTY40KkdMe-DMqdKRJlxOBwoXj-vAba10qJTmNDg$" target="_blank"&gt;https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-48795&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://urldefense.com/v3/__https:/terrapin-attack.com/__;!!KDf9ebxpXGLC!HtQHluwjyktmn2ar_VItyjiRnxbhVY742T6ImLGovIgC7cDngZCthOA0wTY40KkdMe-DMqdKRJlxOBwoXj-vAba10jQ0KNWH$" target="_blank"&gt;https://terrapin-attack.com/&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Response to CVE-2023-48795 from other vendors&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://urldefense.com/v3/__https:/support.checkpoint.com/results/sk/sk181833__;!!KDf9ebxpXGLC!HtQHluwjyktmn2ar_VItyjiRnxbhVY742T6ImLGovIgC7cDngZCthOA0wTY40KkdMe-DMqdKRJlxOBwoXj-vAba10llqxxn8$" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk181833&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://alas.aws.amazon.com/cve/html/CVE-2023-48795.html" target="_blank"&gt;https://alas.aws.amazon.com/cve/html/CVE-2023-48795.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 05 Jan 2024 04:26:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/custom-signatures/palo-alto-reponse-to-cve-2023-48795/m-p/571858#M489</guid>
      <dc:creator>Black_Sunglass</dc:creator>
      <dc:date>2024-01-05T04:26:09Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto Reponse to CVE-2023-48795</title>
      <link>https://live.paloaltonetworks.com/t5/custom-signatures/palo-alto-reponse-to-cve-2023-48795/m-p/571954#M490</link>
      <description>&lt;P&gt;I don't see a response on this but researching.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 05 Jan 2024 20:33:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/custom-signatures/palo-alto-reponse-to-cve-2023-48795/m-p/571954#M490</guid>
      <dc:creator>Usama-Ahmed</dc:creator>
      <dc:date>2024-01-05T20:33:50Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto Reponse to CVE-2023-48795</title>
      <link>https://live.paloaltonetworks.com/t5/custom-signatures/palo-alto-reponse-to-cve-2023-48795/m-p/572254#M491</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;security.paloaltonetworks just updated with this CVE:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://security.paloaltonetworks.com/CVE-2023-48795" target="_blank"&gt;https://security.paloaltonetworks.com/CVE-2023-48795&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="display: block; margin-block: 1em; margin-inline: 0px; color: #727272; font-family: Arial, 'Helvetica Neue', Helvetica, sans-serif; font-size: 16px; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; font-weight: 400; letter-spacing: normal; orphans: 2; text-align: start; text-indent: 0px; text-transform: none; widows: 2; word-spacing: 0px; -webkit-text-stroke-width: 0px; white-space: normal; background-color: #ffffff; text-decoration-thickness: initial; text-decoration-style: initial; text-decoration-color: initial;"&gt;"Customers can resolve this issue by removing support for CHACHA20-POLY1305 and all Encrypt-then-MAC algorithms available (ciphers with -etm in the name) in PAN-OS software. Guidance on how to configure strong ciphers and algorithms can be found on the following pages:&lt;/P&gt;
&lt;P style="display: block; margin-block: 1em; margin-inline: 0px; color: #727272; font-family: Arial, 'Helvetica Neue', Helvetica, sans-serif; font-size: 16px; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; font-weight: 400; letter-spacing: normal; orphans: 2; text-align: start; text-indent: 0px; text-transform: none; widows: 2; word-spacing: 0px; -webkit-text-stroke-width: 0px; white-space: normal; background-color: #ffffff; text-decoration-thickness: initial; text-decoration-style: initial; text-decoration-color: initial;"&gt;-&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A class="linkified" style="text-decoration: none; color: #fa582d;" href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u0000004OOQCA2" target="_blank" rel="noopener"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u0000004OOQCA2&lt;/A&gt;&lt;/P&gt;
&lt;P style="display: block; margin-block: 1em; margin-inline: 0px; color: #727272; font-family: Arial, 'Helvetica Neue', Helvetica, sans-serif; font-size: 16px; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; font-weight: 400; letter-spacing: normal; orphans: 2; text-align: start; text-indent: 0px; text-transform: none; widows: 2; word-spacing: 0px; -webkit-text-stroke-width: 0px; white-space: normal; background-color: #ffffff; text-decoration-thickness: initial; text-decoration-style: initial; text-decoration-color: initial;"&gt;-&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A class="linkified" style="text-decoration: none; color: #fa582d;" href="https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-cli-quick-start/get-started-with-the-cli/refresh-ssh-keys-mgt-port-connection" target="_blank" rel="noopener"&gt;https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-cli-quick-start/get-started-with-the-cli/refresh-ssh-keys-mgt-port-connection&lt;/A&gt;&lt;/P&gt;
&lt;P style="display: block; margin-block: 1em; margin-inline: 0px; color: #727272; font-family: Arial, 'Helvetica Neue', Helvetica, sans-serif; font-size: 16px; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; font-weight: 400; letter-spacing: normal; orphans: 2; text-align: start; text-indent: 0px; text-transform: none; widows: 2; word-spacing: 0px; -webkit-text-stroke-width: 0px; white-space: normal; background-color: #ffffff; text-decoration-thickness: initial; text-decoration-style: initial; text-decoration-color: initial;"&gt;This issue is completely resolved by following the recommended best practices for deploying PAN-OS (&lt;A class="linkified" style="text-decoration: none; color: #fa582d;" href="https://docs.paloaltonetworks.com/best-practices/10-1/administrative-access-best-practices/administrative-access-best-practices/deploy-administrative-access-best-practices" target="_blank" rel="noopener"&gt;https://docs.paloaltonetworks.com/best-practices/10-1/administrative-access-best-practices/administrative-access-best-practices/deploy-administrative-access-best-practices&lt;/A&gt;). No additional PAN-OS fixes are planned in maintenance releases at this time."&lt;/P&gt;</description>
      <pubDate>Tue, 09 Jan 2024 05:42:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/custom-signatures/palo-alto-reponse-to-cve-2023-48795/m-p/572254#M491</guid>
      <dc:creator>hamzah_pinadi</dc:creator>
      <dc:date>2024-01-09T05:42:49Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto Reponse to CVE-2023-48795</title>
      <link>https://live.paloaltonetworks.com/t5/custom-signatures/palo-alto-reponse-to-cve-2023-48795/m-p/572559#M492</link>
      <description>&lt;P&gt;Thanks for the update.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 10 Jan 2024 14:10:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/custom-signatures/palo-alto-reponse-to-cve-2023-48795/m-p/572559#M492</guid>
      <dc:creator>Usama-Ahmed</dc:creator>
      <dc:date>2024-01-10T14:10:11Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto Reponse to CVE-2023-48795</title>
      <link>https://live.paloaltonetworks.com/t5/custom-signatures/palo-alto-reponse-to-cve-2023-48795/m-p/572697#M493</link>
      <description>&lt;P&gt;May we know about&amp;nbsp;&lt;SPAN&gt;CHACHA20-POLY1305 Cipher.&lt;BR /&gt;how can we check in CLI or WEB interface.&lt;BR /&gt;how do we enable to disable this?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 11 Jan 2024 11:18:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/custom-signatures/palo-alto-reponse-to-cve-2023-48795/m-p/572697#M493</guid>
      <dc:creator>Rajendra-S</dc:creator>
      <dc:date>2024-01-11T11:18:31Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto Reponse to CVE-2023-48795</title>
      <link>https://live.paloaltonetworks.com/t5/custom-signatures/palo-alto-reponse-to-cve-2023-48795/m-p/572737#M494</link>
      <description>&lt;P&gt;Hi Rajendra:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You can run the below command from a linux machine against the firewall or Panorama:&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 12.0pt;"&gt;nmap --script ssh2-enum-algos -sV -p 22 &amp;lt;firewall IP&amp;gt;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 12.0pt;"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;That will tell you what ciphers are running on the device. Instructions on that are in this article:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000kF2eCAE&amp;amp;lang=en_US%E2%80%A9" target="_blank" rel="noopener"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000kF2eCAE&amp;amp;lang=en_US%E2%80%A9&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Once you have that information. You can use the article below to disable the undesired ciphers:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u0000004OOQCA2" target="_blank" rel="noopener"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u0000004OOQCA2&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;To alleviate&amp;nbsp;CVE-2023-48795 my understanding is that you need to disable ciphers with -etm in the name. Which if you are on PAN-OS 10.1 would be the below list for MAC algorithms:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV&gt;&lt;SPAN data-ogsc="rgb(0, 0, 0)"&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;umac-64-etm@openssh.com&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN data-ogsc="rgb(0, 0, 0)"&gt;| &amp;nbsp; &amp;nbsp; &amp;nbsp; umac-128-etm@openssh.com&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN data-ogsc="rgb(0, 0, 0)"&gt;| &amp;nbsp; &amp;nbsp; &amp;nbsp; hmac-sha2-256-etm@openssh.com&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN data-ogsc="rgb(0, 0, 0)"&gt;| &amp;nbsp; &amp;nbsp; &amp;nbsp; hmac-sha2-512-etm@openssh.com&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN data-ogsc="rgb(0, 0, 0)"&gt;| &amp;nbsp; &amp;nbsp; &amp;nbsp; hmac-sha1-etm@openssh.com&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV&gt;You should also see in PAN-OS 10.1 in encryption algorithms that you need to disable:&lt;/DIV&gt;
&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN&gt;chacha20-poly1305@openssh.com&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN data-ogsc="rgb(0, 0, 0)"&gt;You can disable more weak ciphers as per your organizational standard to further harden.&amp;nbsp;&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN data-ogsc="rgb(0, 0, 0)"&gt;Reminder, when you use an SSH service profile it becomes an allow list of ciphers, and everything else is blocked.&amp;nbsp;&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN data-ogsc="rgb(0, 0, 0)"&gt;Note: You will have to restart the management SSH service from the CLI to apply the profile using the command "&lt;STRONG&gt;set ssh service-restart mgmt&lt;/STRONG&gt;". It is recommended to do that after hours.&amp;nbsp;&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 11 Jan 2024 15:11:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/custom-signatures/palo-alto-reponse-to-cve-2023-48795/m-p/572737#M494</guid>
      <dc:creator>Usama-Ahmed</dc:creator>
      <dc:date>2024-01-11T15:11:57Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto Reponse to CVE-2023-48795</title>
      <link>https://live.paloaltonetworks.com/t5/custom-signatures/palo-alto-reponse-to-cve-2023-48795/m-p/572802#M495</link>
      <description>&lt;P&gt;Hello Usman Ahmed,&lt;/P&gt;
&lt;P&gt;Thank you for your response.&lt;/P&gt;
&lt;P&gt;Is there any way to check from a Windows or MAC machine?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 12 Jan 2024 00:55:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/custom-signatures/palo-alto-reponse-to-cve-2023-48795/m-p/572802#M495</guid>
      <dc:creator>Rajendra-S</dc:creator>
      <dc:date>2024-01-12T00:55:53Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto Reponse to CVE-2023-48795</title>
      <link>https://live.paloaltonetworks.com/t5/custom-signatures/palo-alto-reponse-to-cve-2023-48795/m-p/1226888#M710</link>
      <description>&lt;P&gt;Hey Rajenda,&lt;/P&gt;
&lt;P&gt;If you need to use any other OS other than Linux, please follow the KB linked below:&lt;/P&gt;
&lt;P&gt;How to view the SSH cipher suites supported on the Firewall using non-Palo Alto Networks tools&lt;BR /&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u0000008WoTCAU" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u0000008WoTCAU&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 18 Apr 2025 09:28:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/custom-signatures/palo-alto-reponse-to-cve-2023-48795/m-p/1226888#M710</guid>
      <dc:creator>aadamczyk</dc:creator>
      <dc:date>2025-04-18T09:28:31Z</dc:date>
    </item>
  </channel>
</rss>

