<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic CVE-2023-48795 Vulnerability in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/cve-2023-48795-vulnerability/m-p/1231412#M124530</link>
    <description>&lt;P&gt;Hi Community,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have my firewall been exposed to&amp;nbsp;&lt;SPAN&gt;CVE-2023-48795&amp;nbsp;Impact of Terrapin SSH Attack. Currently, based on the Palo Alto Security Advisories, I could see that PAN-OS version that are above than 10.1.15 are unaffected to this CVE. Upon checking my firewall model which is PA-820, I couldn't see any version listed for 10.1.15 in the software updates.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'm not quite sure why it isn't listed for my model. Hope someone can enlighten me regarding this and should I proceed to upgrade to another version chain or proceed with the recommended solutions stated in the Security Advisories?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Model: PA-820&lt;/P&gt;
&lt;P&gt;Running Version: 10.1.14-h9&lt;/P&gt;</description>
    <pubDate>Tue, 10 Jun 2025 11:28:38 GMT</pubDate>
    <dc:creator>SyafiqBharudin</dc:creator>
    <dc:date>2025-06-10T11:28:38Z</dc:date>
    <item>
      <title>CVE-2023-48795 Vulnerability</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cve-2023-48795-vulnerability/m-p/1231412#M124530</link>
      <description>&lt;P&gt;Hi Community,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have my firewall been exposed to&amp;nbsp;&lt;SPAN&gt;CVE-2023-48795&amp;nbsp;Impact of Terrapin SSH Attack. Currently, based on the Palo Alto Security Advisories, I could see that PAN-OS version that are above than 10.1.15 are unaffected to this CVE. Upon checking my firewall model which is PA-820, I couldn't see any version listed for 10.1.15 in the software updates.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'm not quite sure why it isn't listed for my model. Hope someone can enlighten me regarding this and should I proceed to upgrade to another version chain or proceed with the recommended solutions stated in the Security Advisories?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Model: PA-820&lt;/P&gt;
&lt;P&gt;Running Version: 10.1.14-h9&lt;/P&gt;</description>
      <pubDate>Tue, 10 Jun 2025 11:28:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cve-2023-48795-vulnerability/m-p/1231412#M124530</guid>
      <dc:creator>SyafiqBharudin</dc:creator>
      <dc:date>2025-06-10T11:28:38Z</dc:date>
    </item>
    <item>
      <title>Re: CVE-2023-48795 Vulnerability</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cve-2023-48795-vulnerability/m-p/1231418#M124531</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/785263569"&gt;@SyafiqBharudin&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You have likely checked "Preferred Releases" or "Base Releases" at the bottom of the Software page.&lt;BR /&gt;Uncheck and try again.&amp;nbsp; All available releases should become visible.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="kiwi_0-1749557938065.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/67984iC62A80A5533D05CD/image-size/medium?v=v2&amp;amp;px=400" role="button" title="kiwi_0-1749557938065.png" alt="kiwi_0-1749557938065.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope this helps,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Kind regards,&lt;/P&gt;
&lt;P&gt;-Kim.&lt;/P&gt;</description>
      <pubDate>Tue, 10 Jun 2025 12:19:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cve-2023-48795-vulnerability/m-p/1231418#M124531</guid>
      <dc:creator>kiwi</dc:creator>
      <dc:date>2025-06-10T12:19:35Z</dc:date>
    </item>
    <item>
      <title>Re: CVE-2023-48795 Vulnerability</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cve-2023-48795-vulnerability/m-p/1231455#M124539</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/785263569"&gt;@SyafiqBharudin&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;10.1.15 doesn't exist, you can verify by looking at the release notes for PAN-OS 10.1&amp;nbsp;&lt;A href="https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-release-notes/" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-release-notes/&lt;/A&gt;. The latest release is 10.1.14-h14 and PAN didn't actually include any detailed release notes in that version. Short of jumping major versions, you would need to reach out to TAC to get an estimate of 10.1.15 release date or verify whether this was one of the issues addressed in 10.1.14-h14 that they didn't feel like detailing.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In other releases, and under normal situations, PAN details CVEs pretty extensively when fixes are made to address them. This leads me to believe that the fix actually isn't out yet for 10.1 for some reason.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 10 Jun 2025 21:16:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cve-2023-48795-vulnerability/m-p/1231455#M124539</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2025-06-10T21:16:13Z</dc:date>
    </item>
  </channel>
</rss>

