<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Vulnerability Assessment  against Panorama found two vulnerability in Panorama Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/panorama-discussions/vulnerability-assessment-against-panorama-found-two/m-p/565951#M2008</link>
    <description>&lt;P&gt;Hi Support,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Recently we have Vulnerability Assessment and found two vulnerability on Panorama&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;1.&amp;nbsp;“The remote HTTPS server is not enforcing HTTP Strict Transport Security (HSTS)&amp;nbsp;on Port 28443&lt;BR /&gt;&lt;BR /&gt;2.“SSL Certificate Cannot Be Trusted” for port 28270.&lt;BR /&gt;&lt;BR /&gt;How can we remediate on both vulnerability above?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Any advise and solution much appreciated&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Thank you&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;Fariq&lt;/P&gt;</description>
    <pubDate>Thu, 16 Nov 2023 09:06:10 GMT</pubDate>
    <dc:creator>Fariq_Zaidi</dc:creator>
    <dc:date>2023-11-16T09:06:10Z</dc:date>
    <item>
      <title>Vulnerability Assessment  against Panorama found two vulnerability</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/vulnerability-assessment-against-panorama-found-two/m-p/565951#M2008</link>
      <description>&lt;P&gt;Hi Support,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Recently we have Vulnerability Assessment and found two vulnerability on Panorama&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;1.&amp;nbsp;“The remote HTTPS server is not enforcing HTTP Strict Transport Security (HSTS)&amp;nbsp;on Port 28443&lt;BR /&gt;&lt;BR /&gt;2.“SSL Certificate Cannot Be Trusted” for port 28270.&lt;BR /&gt;&lt;BR /&gt;How can we remediate on both vulnerability above?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Any advise and solution much appreciated&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Thank you&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;Fariq&lt;/P&gt;</description>
      <pubDate>Thu, 16 Nov 2023 09:06:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/vulnerability-assessment-against-panorama-found-two/m-p/565951#M2008</guid>
      <dc:creator>Fariq_Zaidi</dc:creator>
      <dc:date>2023-11-16T09:06:10Z</dc:date>
    </item>
    <item>
      <title>Re: Vulnerability Assessment  against Panorama found two vulnerability</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/vulnerability-assessment-against-panorama-found-two/m-p/566423#M2009</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/225107"&gt;@Fariq_Zaidi&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Port 28443 is specifically utilized for downloading content files from Panorama by firewalls. On the other hand, port 28270 is employed for communication between Panorama and managed firewalls or managed collectors.&lt;/P&gt;
&lt;P&gt;It's important to note that these ports facilitate communication between Palo Alto devices and proper certificate validations are enforced in this communication. The certificates involved can be self-signed. Consequently, the alerts you are observing could be triggered by external tools attempting connection or checks, which may not fully validate the certificates in use.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 21 Nov 2023 03:57:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/vulnerability-assessment-against-panorama-found-two/m-p/566423#M2009</guid>
      <dc:creator>akuzhuppilly</dc:creator>
      <dc:date>2023-11-21T03:57:43Z</dc:date>
    </item>
    <item>
      <title>Re: Vulnerability Assessment  against Panorama found two vulnerability</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/vulnerability-assessment-against-panorama-found-two/m-p/594050#M2421</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/225107"&gt;@Fariq_Zaidi&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;the issue you described has own KB:&amp;nbsp;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000saRLCAY" target="_self"&gt;A vulnerability "HSTS Missing From HTTPS Server" is reported on Panorama on port TCP/28443&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Kind Regards&lt;/P&gt;
&lt;P&gt;Pavel&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 05 Aug 2024 22:50:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/vulnerability-assessment-against-panorama-found-two/m-p/594050#M2421</guid>
      <dc:creator>PavelK</dc:creator>
      <dc:date>2024-08-05T22:50:18Z</dc:date>
    </item>
  </channel>
</rss>

