<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: CVE-2021-3059 - clarity on disabling dynamic updates in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/cve-2021-3059-clarity-on-disabling-dynamic-updates/m-p/446880#M100638</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/138646"&gt;@BSwientoniowski&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;If your running Panorama you would want to do it in both locations for full mediation. Device Deployment &amp;gt; Dynamic Updates is simply using Panorama to deploy the dynamic updates to your firewalls, where's Device Tab &amp;gt; Dynamic Updates is having Panorama (or just a standalone firewall) reach out to PANs update network to grab the updates.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As for the manual installation, assuming that you aren't concerned about MITM within your own network, this should be fine from what they've published.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 11 Nov 2021 05:03:49 GMT</pubDate>
    <dc:creator>BPry</dc:creator>
    <dc:date>2021-11-11T05:03:49Z</dc:date>
    <item>
      <title>CVE-2021-3059 - clarity on disabling dynamic updates</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cve-2021-3059-clarity-on-disabling-dynamic-updates/m-p/446807#M100630</link>
      <description>&lt;P data-unlink="true"&gt;The &lt;A href="https://security.paloaltonetworks.com/CVE-2021-3059" target="_self"&gt;Security Advisory for CVE-2021-3059&lt;/A&gt; &amp;nbsp;suggests disabling dynamic updates as a workaround for the vulnerability.&amp;nbsp; However, it specifically says to go to the &lt;STRONG&gt;Device Deployment &amp;gt; Dynamic Updates&amp;nbsp;&lt;/STRONG&gt;interface (which is in the Panorama tab of my deployment).&lt;/P&gt;&lt;P data-unlink="true"&gt;&amp;nbsp;&lt;/P&gt;&lt;P data-unlink="true"&gt;How is that different than if you have schedules set under the Device Tab &amp;gt; Dynamic Updates?&lt;/P&gt;&lt;P data-unlink="true"&gt;&amp;nbsp;&lt;/P&gt;&lt;P data-unlink="true"&gt;Additionally, is it OK to manually download and install app/threat, av, and wildfire updates?&lt;/P&gt;</description>
      <pubDate>Wed, 10 Nov 2021 20:13:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cve-2021-3059-clarity-on-disabling-dynamic-updates/m-p/446807#M100630</guid>
      <dc:creator>BSwientoniowski</dc:creator>
      <dc:date>2021-11-10T20:13:02Z</dc:date>
    </item>
    <item>
      <title>Re: CVE-2021-3059 - clarity on disabling dynamic updates</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cve-2021-3059-clarity-on-disabling-dynamic-updates/m-p/446835#M100631</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;So this is only my opinion, however I say keep the dynamic updates on. The risk is very low even according to the article. An attacker would have to play man in the middle with PAN's certificates and DNS resolution to pull this off. I would say the risk is higher if you disable the dynamic updates. However yes you can do them manually.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Wed, 10 Nov 2021 22:39:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cve-2021-3059-clarity-on-disabling-dynamic-updates/m-p/446835#M100631</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2021-11-10T22:39:12Z</dc:date>
    </item>
    <item>
      <title>Re: CVE-2021-3059 - clarity on disabling dynamic updates</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cve-2021-3059-clarity-on-disabling-dynamic-updates/m-p/446880#M100638</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/138646"&gt;@BSwientoniowski&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;If your running Panorama you would want to do it in both locations for full mediation. Device Deployment &amp;gt; Dynamic Updates is simply using Panorama to deploy the dynamic updates to your firewalls, where's Device Tab &amp;gt; Dynamic Updates is having Panorama (or just a standalone firewall) reach out to PANs update network to grab the updates.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As for the manual installation, assuming that you aren't concerned about MITM within your own network, this should be fine from what they've published.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 11 Nov 2021 05:03:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cve-2021-3059-clarity-on-disabling-dynamic-updates/m-p/446880#M100638</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2021-11-11T05:03:49Z</dc:date>
    </item>
    <item>
      <title>Re: CVE-2021-3059 - clarity on disabling dynamic updates</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cve-2021-3059-clarity-on-disabling-dynamic-updates/m-p/447013#M100648</link>
      <description>&lt;P&gt;I fully agree with &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp; and &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/27580"&gt;@OtakarKlier&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I was surprise that the advisory is not mentioning the "verify update server identity" as possible workaround...&lt;/P&gt;
&lt;P&gt;How will you perform MITM if firewall accept only publicy trusted CAs, it is hard to imagine that attacker will be able to get public CA sign his forget certificate...&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 11 Nov 2021 15:35:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cve-2021-3059-clarity-on-disabling-dynamic-updates/m-p/447013#M100648</guid>
      <dc:creator>aleksandar.astardzhiev</dc:creator>
      <dc:date>2021-11-11T15:35:24Z</dc:date>
    </item>
  </channel>
</rss>

