<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Vulnerability scan showing CVE-2008-4309 - SNMP 'GETBULK' Reflection DDoS in Advanced Threat Prevention Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/vulnerability-scan-showing-cve-2008-4309-snmp-getbulk-reflection/m-p/590844#M2236</link>
    <description>&lt;P&gt;Not seeing anything on this anywhere I search. Nessus is showing&amp;nbsp;CVE-2008-4309 - SNMP 'GETBULK' Reflection DDoS on our PA-1410 on 11.0.3-h10.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Nessus was able to determine the SNMP service can be abused in an SNMP&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Reflection DDoS attack :&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Request size (bytes) : 42&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Response size (bytes) : 2341&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Not sure what I should do to remedy this alert. Thanks for any thoughts or suggestions.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 01 Jul 2024 17:24:53 GMT</pubDate>
    <dc:creator>inSync-MarkValpreda</dc:creator>
    <dc:date>2024-07-01T17:24:53Z</dc:date>
    <item>
      <title>Vulnerability scan showing CVE-2008-4309 - SNMP 'GETBULK' Reflection DDoS</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/vulnerability-scan-showing-cve-2008-4309-snmp-getbulk-reflection/m-p/590844#M2236</link>
      <description>&lt;P&gt;Not seeing anything on this anywhere I search. Nessus is showing&amp;nbsp;CVE-2008-4309 - SNMP 'GETBULK' Reflection DDoS on our PA-1410 on 11.0.3-h10.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Nessus was able to determine the SNMP service can be abused in an SNMP&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Reflection DDoS attack :&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Request size (bytes) : 42&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Response size (bytes) : 2341&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Not sure what I should do to remedy this alert. Thanks for any thoughts or suggestions.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 01 Jul 2024 17:24:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/vulnerability-scan-showing-cve-2008-4309-snmp-getbulk-reflection/m-p/590844#M2236</guid>
      <dc:creator>inSync-MarkValpreda</dc:creator>
      <dc:date>2024-07-01T17:24:53Z</dc:date>
    </item>
    <item>
      <title>Re: Vulnerability scan showing CVE-2008-4309 - SNMP 'GETBULK' Reflection DDoS</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/vulnerability-scan-showing-cve-2008-4309-snmp-getbulk-reflection/m-p/1262914#M2518</link>
      <description>&lt;P&gt;Hey man, did u manage to fix this issue?&amp;nbsp; Appreciate your response.&lt;/P&gt;
&lt;P&gt;i had the same issue as well.&lt;/P&gt;
&lt;P&gt;VA Scan points out:&lt;BR /&gt;CVE-1999-0517 (SNMP Agent Default Community Name (public))&amp;nbsp;&lt;/P&gt;
&lt;P&gt;CVE-2008-4309 (SNMP 'GETBULK' Reflection DDoS&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I had to remediate these two but same, i do not see any public way to resolve this. Also i am using v3 so the first CVE im not sure if its false positive.&lt;/P&gt;</description>
      <pubDate>Wed, 26 Aug 2026 08:42:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/vulnerability-scan-showing-cve-2008-4309-snmp-getbulk-reflection/m-p/1262914#M2518</guid>
      <dc:creator>H.Najwan</dc:creator>
      <dc:date>2026-08-26T08:42:57Z</dc:date>
    </item>
    <item>
      <title>Re: Vulnerability scan showing CVE-2008-4309 - SNMP 'GETBULK' Reflection DDoS</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/vulnerability-scan-showing-cve-2008-4309-snmp-getbulk-reflection/m-p/1263533#M2521</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="PDq2pG_selectionAnchorContainer" data-end="434" data-start="0"&gt;That Nessus result is most likely &lt;STRONG data-end="121" data-start="34"&gt;not saying your PA-1410 is specifically vulnerable to an old Palo Alto software bug&lt;/STRONG&gt;. Tenable’s plugin is detecting a behavior: the firewall’s SNMP service accepts a small &lt;CODE data-end="218" data-start="209"&gt;GETBULK&lt;/CODE&gt; request and returns a much larger response, which means it could potentially be used as an &lt;STRONG data-end="350" data-start="310"&gt;SNMP reflection/amplification source&lt;/STRONG&gt;. Tenable maps that behavior to CVE-2008-4309.&lt;/P&gt;
&lt;P data-end="479" data-start="436"&gt;Your numbers make the concern pretty clear:&lt;/P&gt;
&lt;UL data-end="569" data-start="481"&gt;
&lt;LI data-end="504" data-start="481" data-section-id="yebi70"&gt;Request: &lt;STRONG data-end="504" data-start="492"&gt;42 bytes&lt;/STRONG&gt;&lt;/LI&gt;
&lt;LI data-end="531" data-start="505" data-section-id="4yz88c"&gt;Response: &lt;STRONG data-end="531" data-start="517"&gt;2341 bytes&lt;/STRONG&gt;&lt;/LI&gt;
&lt;LI data-end="569" data-start="532" data-section-id="1a80lda"&gt;Amplification factor: about &lt;STRONG data-end="569" data-start="562"&gt;56×&lt;/STRONG&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P data-end="707" data-start="571"&gt;The primary remediation is therefore &lt;STRONG data-end="639" data-start="608"&gt;restrict who can query SNMP&lt;/STRONG&gt;, rather than looking for a PAN-OS hotfix specifically for that CVE.&lt;/P&gt;
&lt;P data-end="764" data-start="709"&gt;For a PA-1410, I would check these items in this order:&lt;/P&gt;
&lt;OL data-end="2118" data-start="766"&gt;
&lt;LI data-end="1100" data-start="766" data-section-id="1yc6sa5"&gt;&lt;STRONG data-end="807" data-start="769"&gt;Do you actually need SNMP polling?&lt;/STRONG&gt;&lt;BR data-end="810" data-start="807" /&gt;If not, disable SNMP on the interface Nessus is scanning. Palo Alto explicitly recommends disabling unused management services. SNMP polling is enabled either on the MGT interface or through an Interface Management Profile on a data-plane interface.&lt;/LI&gt;
&lt;LI data-end="2118" data-start="1102" data-section-id="17irpkm"&gt;
&lt;P data-end="1320" data-start="1105"&gt;&lt;STRONG data-end="1171" data-start="1105"&gt;If you need SNMP, restrict it to only your monitoring servers.&lt;/STRONG&gt;&lt;BR data-end="1174" data-start="1171" /&gt;If Nessus can query the firewall merely because it has network connectivity to that interface, your SNMP exposure is broader than it should be.&lt;/P&gt;
&lt;P data-end="1361" data-start="1325"&gt;For the &lt;STRONG data-end="1360" data-start="1333"&gt;dedicated MGT interface&lt;/STRONG&gt;:&lt;/P&gt;
&lt;P data-end="1410" data-start="1366"&gt;&lt;STRONG data-end="1410" data-start="1366"&gt;Device → Setup → Interfaces → Management&lt;/STRONG&gt;&lt;/P&gt;
&lt;P data-end="1684" data-start="1415"&gt;Make sure &lt;STRONG data-end="1451" data-start="1425"&gt;Permitted IP Addresses&lt;/STRONG&gt; contains only your SNMP/NMS and administrator networks. Palo Alto states that an empty permitted-IP list allows access from any IP address and recommends explicitly specifying allowed addresses.&lt;/P&gt;
&lt;P data-end="1746" data-start="1689"&gt;If SNMP is enabled on a &lt;STRONG data-end="1745" data-start="1713"&gt;Layer 3/data-plane interface&lt;/STRONG&gt;:&lt;/P&gt;
&lt;P data-end="1798" data-start="1751"&gt;&lt;STRONG data-end="1798" data-start="1751"&gt;Network → Network Profiles → Interface Mgmt&lt;/STRONG&gt;&lt;/P&gt;
&lt;P data-end="2118" data-start="1803"&gt;Edit the Interface Management Profile that has &lt;STRONG data-end="1858" data-start="1850"&gt;SNMP&lt;/STRONG&gt; checked, and populate &lt;STRONG data-end="1907" data-start="1881"&gt;Permitted IP Addresses&lt;/STRONG&gt; with only the SNMP monitoring server(s). Palo Alto documents that these profiles control both which management protocols are exposed and which IP addresses can access them.&lt;/P&gt;
&lt;/LI&gt;
&lt;/OL&gt;
&lt;P data-end="2144" data-start="2120"&gt;For example, instead of:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV class="relative w-full mt-4 mb-1"&gt;
&lt;DIV class=""&gt;
&lt;DIV class="contents"&gt;
&lt;DIV class="relative"&gt;
&lt;DIV class="h-full min-h-0 min-w-0"&gt;
&lt;DIV class="h-full min-h-0 min-w-0"&gt;
&lt;DIV class="border border-token-border-light border-radius-3xl corner-superellipse/1.1 rounded-3xl"&gt;
&lt;DIV class="h-full w-full border-radius-3xl bg-(--code-block-surface) corner-superellipse/1.1 overflow-clip rounded-3xl [--code-block-surface:var(--bg-elevated-secondary)] dark:[--code-block-surface:var(--composer-surface-primary)] lxnfua_clipPathFallback"&gt;
&lt;DIV class="pointer-events-none absolute end-1.5 top-1 z-2 md:end-2 md:top-1"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV class="relative"&gt;
&lt;DIV class="pe-11 pt-3"&gt;
&lt;DIV class="relative z-0 flex max-w-full"&gt;
&lt;DIV id="code-block-viewer" class="q9tKkq_viewer cm-editor z-10 light:cm-light dark:cm-light flex h-full w-full flex-col items-stretch ͼs ͼ16" dir="ltr"&gt;
&lt;DIV class="cm-scroller"&gt;
&lt;PRE class="cm-content q9tKkq_readonly m-0"&gt;&lt;CODE&gt;&lt;SPAN&gt;SNMP: enabled
Permitted IP Addresses: &amp;lt;blank&amp;gt;&lt;/SPAN&gt;&lt;/CODE&gt;&lt;/PRE&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV class=""&gt;
&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;PRE class="overflow-visible! px-0!" data-end="2203" data-start="2146"&gt;&amp;nbsp;&lt;/PRE&gt;
&lt;P data-end="2235" data-start="2205"&gt;I'd want something resembling:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV class="relative w-full mt-4 mb-1"&gt;
&lt;DIV class=""&gt;
&lt;DIV class="contents"&gt;
&lt;DIV class="relative"&gt;
&lt;DIV class="h-full min-h-0 min-w-0"&gt;
&lt;DIV class="h-full min-h-0 min-w-0"&gt;
&lt;DIV class="border border-token-border-light border-radius-3xl corner-superellipse/1.1 rounded-3xl"&gt;
&lt;DIV class="h-full w-full border-radius-3xl bg-(--code-block-surface) corner-superellipse/1.1 overflow-clip rounded-3xl [--code-block-surface:var(--bg-elevated-secondary)] dark:[--code-block-surface:var(--composer-surface-primary)] lxnfua_clipPathFallback"&gt;
&lt;DIV class="pointer-events-none absolute end-1.5 top-1 z-2 md:end-2 md:top-1"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV class="relative"&gt;
&lt;DIV class="pe-11 pt-3"&gt;
&lt;DIV class="relative z-0 flex max-w-full"&gt;
&lt;DIV id="code-block-viewer" class="q9tKkq_viewer cm-editor z-10 light:cm-light dark:cm-light flex h-full w-full flex-col items-stretch ͼs ͼ16" dir="ltr"&gt;
&lt;DIV class="cm-scroller"&gt;
&lt;PRE class="cm-content q9tKkq_readonly m-0"&gt;&lt;CODE&gt;&lt;SPAN&gt;SNMP: enabled

Permitted IP Addresses:
10.20.30.15/32   # SolarWinds
10.20.30.16/32   # Secondary NMS&lt;/SPAN&gt;&lt;/CODE&gt;&lt;/PRE&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV class=""&gt;
&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;P&gt;&lt;LI-WRAPPER&gt;&lt;/LI-WRAPPER&gt;&lt;/P&gt;
&lt;PRE class="overflow-visible! px-0!" data-end="2350" data-start="2237"&gt;&amp;nbsp;&lt;/PRE&gt;
&lt;P data-end="2446" data-start="2352"&gt;Then a Nessus scanner at, say, &lt;CODE data-end="2396" data-start="2383"&gt;10.50.10.25&lt;/CODE&gt; should no longer receive an SNMP response at all.&lt;/P&gt;
&lt;P data-end="2727" data-start="2448"&gt;I would also move to &lt;STRONG data-end="2479" data-start="2469"&gt;SNMPv3&lt;/STRONG&gt; if you're currently using v2c. PAN-OS supports both v2c and v3, but Palo Alto identifies v3 as the more secure option because it provides authentication, integrity, encryption/privacy, and granular MIB access.&lt;/P&gt;
&lt;P data-end="2951" data-start="2729"&gt;One caveat: &lt;STRONG data-end="2826" data-start="2741"&gt;SNMPv3 by itself does not necessarily eliminate the amplification characteristic.&lt;/STRONG&gt; The strongest mitigation for this specific finding is preventing arbitrary hosts from talking to UDP/161 in the first place.&lt;/P&gt;
&lt;P data-end="3305" data-start="2953"&gt;There is also another important issue in your environment: &lt;STRONG data-end="3039" data-start="3012"&gt;PAN-OS 11.0 is EoL now.&lt;/STRONG&gt; Palo Alto's current documentation marks the 11.0 train as end-of-life. So independently of this Nessus finding, I would plan to move that PA-1410 to a currently supported PAN-OS release that is appropriate for your environment.&lt;/P&gt;
&lt;P data-end="3367" data-start="3307"&gt;So my remediation ticket would probably read something like:&lt;/P&gt;
&lt;BLOCKQUOTE data-end="3966" data-start="3369"&gt;
&lt;P data-end="3966" data-start="3371"&gt;&lt;STRONG data-end="3383" data-start="3371"&gt;Finding:&lt;/STRONG&gt; SNMP GETBULK reflection/amplification detected on PA-1410.&lt;BR data-end="3445" data-start="3442" /&gt;&lt;STRONG data-end="3457" data-start="3447"&gt;Cause:&lt;/STRONG&gt; Firewall SNMP service responds to queries from systems beyond the authorized SNMP management hosts.&lt;BR data-end="3560" data-start="3557" /&gt;&lt;STRONG data-end="3578" data-start="3562"&gt;Remediation:&lt;/STRONG&gt; Restrict UDP/161 management access using the PAN-OS Management Interface permitted-IP configuration or Interface Management Profile so that only authorized SNMP managers may query the firewall. Where possible, migrate SNMP monitoring from v2c to SNMPv3. Disable SNMP entirely if monitoring is not required. Upgrade PAN-OS from the EoL 11.0 release train to a currently supported release.&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;P data-end="4243" data-start="3968"&gt;One thing I would &lt;STRONG data-end="3993" data-start="3986"&gt;not&lt;/STRONG&gt; do is start building Security Policy / Vulnerability Protection rules to block &lt;CODE data-end="4082" data-start="4073"&gt;GETBULK&lt;/CODE&gt; against the firewall itself. If Nessus is hitting the firewall's own management service, &lt;STRONG data-end="4242" data-start="4172"&gt;management-plane/interface access controls are the correct control&lt;/STRONG&gt;.&lt;/P&gt;
&lt;P data-end="4500" data-start="4245"&gt;Also, &lt;STRONG data-end="4312" data-start="4251"&gt;11.0.3-h10 is quite old within an already-EoL 11.0 branch&lt;/STRONG&gt;, so I would not spend much effort trying to determine whether some later 11.0 hotfix changes this exact Nessus behavior. Restrict SNMP first, then deal with the PAN-OS upgrade separately.&lt;/P&gt;</description>
      <pubDate>Wed, 02 Sep 2026 18:08:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/vulnerability-scan-showing-cve-2008-4309-snmp-getbulk-reflection/m-p/1263533#M2521</guid>
      <dc:creator>S.Cantwell</dc:creator>
      <dc:date>2026-09-02T18:08:18Z</dc:date>
    </item>
  </channel>
</rss>

