<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How to solve &amp;quot;CWE-693 : Protection Mechanism Failure&amp;quot; in Paloalto firewall in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-solve-quot-cwe-693-protection-mechanism-failure-quot-in/m-p/198922#M59011</link>
    <description>&lt;P&gt;Hello Geeks,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;During our compliance scanning (PCI-DSS External Scanning) process on our paloalto 3020 firewalls, the scanner found new vulnerability, "CWE-693 : Protection Mechanism Failure" and suggested to fix it ASAP to comply. Hence, I started googling to solve this issues and found no useful solutions for this yet. Is there any way to solve this issue and I am sure that every organization trying to comply with PCIDSS external scanning process are facing this issue now. Really appreciate for your kind suggestions and help.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best Regards,&lt;/P&gt;&lt;P&gt;Wai Yan Phyo&lt;/P&gt;</description>
    <pubDate>Tue, 06 Feb 2018 03:38:32 GMT</pubDate>
    <dc:creator>Wayne88</dc:creator>
    <dc:date>2018-02-06T03:38:32Z</dc:date>
    <item>
      <title>How to solve "CWE-693 : Protection Mechanism Failure" in Paloalto firewall</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-solve-quot-cwe-693-protection-mechanism-failure-quot-in/m-p/198922#M59011</link>
      <description>&lt;P&gt;Hello Geeks,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;During our compliance scanning (PCI-DSS External Scanning) process on our paloalto 3020 firewalls, the scanner found new vulnerability, "CWE-693 : Protection Mechanism Failure" and suggested to fix it ASAP to comply. Hence, I started googling to solve this issues and found no useful solutions for this yet. Is there any way to solve this issue and I am sure that every organization trying to comply with PCIDSS external scanning process are facing this issue now. Really appreciate for your kind suggestions and help.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best Regards,&lt;/P&gt;&lt;P&gt;Wai Yan Phyo&lt;/P&gt;</description>
      <pubDate>Tue, 06 Feb 2018 03:38:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-solve-quot-cwe-693-protection-mechanism-failure-quot-in/m-p/198922#M59011</guid>
      <dc:creator>Wayne88</dc:creator>
      <dc:date>2018-02-06T03:38:32Z</dc:date>
    </item>
    <item>
      <title>Re: How to solve "CWE-693 : Protection Mechanism Failure" in Paloalto firewall</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-solve-quot-cwe-693-protection-mechanism-failure-quot-in/m-p/198988#M59018</link>
      <description>&lt;P&gt;Does the scan provide a subdivision of detected failures?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;the CWE seems to be an extremely broad statement that can't be addressed in itself (besides pulling the plug)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Did you scan the management interface or a dataplane management profile, have you got weak services enabled (telnet, http, ..) maybe ?&lt;/P&gt;</description>
      <pubDate>Tue, 06 Feb 2018 10:46:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-solve-quot-cwe-693-protection-mechanism-failure-quot-in/m-p/198988#M59018</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2018-02-06T10:46:12Z</dc:date>
    </item>
    <item>
      <title>Re: How to solve "CWE-693 : Protection Mechanism Failure" in Paloalto firewall</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-solve-quot-cwe-693-protection-mechanism-failure-quot-in/m-p/199205#M59059</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hi Reaper,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for your kind response.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The scanner provided the following HTTP headers are absent in our firewall.&lt;/P&gt;&lt;P&gt;X-XSS-Protection&lt;BR /&gt;X-Frame-Options&lt;BR /&gt;X-Content-Type-Options:&lt;BR /&gt;Public-Key-Pins&lt;BR /&gt;Strict-Transport-Security&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As this is external compliance scanning, the public-facing (external) interface was scanned and we didn't enable any insecure services like telnet and http.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 07 Feb 2018 03:03:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-solve-quot-cwe-693-protection-mechanism-failure-quot-in/m-p/199205#M59059</guid>
      <dc:creator>Wayne88</dc:creator>
      <dc:date>2018-02-07T03:03:42Z</dc:date>
    </item>
    <item>
      <title>Re: How to solve "CWE-693 : Protection Mechanism Failure" in Paloalto firewall</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-solve-quot-cwe-693-protection-mechanism-failure-quot-in/m-p/199255#M59067</link>
      <description>&lt;P&gt;Is there a management profile enabled on your external interface?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;There are a couple of tips to improve security on your external interface:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Don't run a management profile on it, use GlobalProtect instead to get to the internal network and connect from there. If this is not an option, enable an ACL on the management profile restricting access to only a select few management IPS&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If this was not a mgmt profile but GP portal/gateway, you can move the portal and gateway to a loopback interface so you can create a security profile to protect the portal/gw&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If this was a scan that hit a NAT rule (so a scan rerouted to an internal server), you'll need to review your internal server, but you can add a decryption policy with a decryption profile that enforces minimum protocol version and algorithms&lt;/P&gt;</description>
      <pubDate>Wed, 07 Feb 2018 09:48:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-solve-quot-cwe-693-protection-mechanism-failure-quot-in/m-p/199255#M59067</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2018-02-07T09:48:34Z</dc:date>
    </item>
    <item>
      <title>Re: How to solve "CWE-693 : Protection Mechanism Failure" in Paloalto firewall</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-solve-quot-cwe-693-protection-mechanism-failure-quot-in/m-p/199508#M59122</link>
      <description>&lt;P&gt;- There is no management profile enabled on this external interface.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;- Yes, this is just used for GlobalProtect portal / gateway.&amp;nbsp; We may consider to use it with a loopback and set security profiles on it as per your suggestions.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;- Apart from these secure protection on firewall, is there any other HTTP header protection which can be enabled on the firewall? I am asking that because the scanner would show the same unprotected vulnerability in the report after scanning&amp;nbsp;due to the lack of&amp;nbsp;its' suggested protection methods enabled on the firewall.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;- Only manual verification / testing would approve that the device is protecting itself from these mentioned risks. Also we are not sure if&amp;nbsp;ASV would accept these secure and hardening ways as compensation control to mitigate this vulnerability.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;However, we really appreciate for your kind, patient and continuous suggestions and supports.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 08 Feb 2018 05:00:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-solve-quot-cwe-693-protection-mechanism-failure-quot-in/m-p/199508#M59122</guid>
      <dc:creator>Wayne88</dc:creator>
      <dc:date>2018-02-08T05:00:59Z</dc:date>
    </item>
    <item>
      <title>Re: How to solve "CWE-693 : Protection Mechanism Failure" in Paloalto firewall</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-solve-quot-cwe-693-protection-mechanism-failure-quot-in/m-p/199560#M59127</link>
      <description>&lt;P&gt;The GP portal and gateway are already hardened but putting a security profile on top would block incoming scans or exploits for potentially vulnerable services before they hit the service itself.&lt;/P&gt;
&lt;P&gt;Legitimate connections where something is reported as missing would still come back, but an actual exploit will be blocked by the profile&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;you could reach out to your local sales team to have a more thorough investigation of your configuration, they can run best practices and recommendations tools on your config and make more in-depth analysis of your situation and possibly provide better tailored mitigation advise&lt;/P&gt;</description>
      <pubDate>Thu, 08 Feb 2018 10:51:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-solve-quot-cwe-693-protection-mechanism-failure-quot-in/m-p/199560#M59127</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2018-02-08T10:51:47Z</dc:date>
    </item>
    <item>
      <title>Re: How to solve "CWE-693 : Protection Mechanism Failure" in Paloalto firewall</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-solve-quot-cwe-693-protection-mechanism-failure-quot-in/m-p/211407#M61682</link>
      <description>&lt;P&gt;Having same issue, however i am getting this not on the GP interface but another. How did you solve this?&lt;/P&gt;</description>
      <pubDate>Mon, 23 Apr 2018 21:19:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-solve-quot-cwe-693-protection-mechanism-failure-quot-in/m-p/211407#M61682</guid>
      <dc:creator>sruddy</dc:creator>
      <dc:date>2018-04-23T21:19:03Z</dc:date>
    </item>
    <item>
      <title>Re: How to solve "CWE-693 : Protection Mechanism Failure" in Paloalto firewall</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-solve-quot-cwe-693-protection-mechanism-failure-quot-in/m-p/211445#M61688</link>
      <description>&lt;P&gt;Hi Sruddy,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;PA recommend to upgrdate to PAN OS 8.0.8 to mitigate this vulnerability. This upgrade will enable the following http headers in PA firewall.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT color="black"&gt;X-XSS-Protection&lt;/FONT&gt;&lt;FONT color="black"&gt;&lt;BR /&gt;X-Content-Type-Options&lt;/FONT&gt;&lt;FONT color="black"&gt;&lt;BR /&gt;Content-Security-Policy&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT color="black"&gt;Thank you.&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT color="black"&gt;Best Regards,&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="black"&gt;Wai Yan&lt;/FONT&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 24 Apr 2018 06:52:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-solve-quot-cwe-693-protection-mechanism-failure-quot-in/m-p/211445#M61688</guid>
      <dc:creator>Wayne88</dc:creator>
      <dc:date>2018-04-24T06:52:55Z</dc:date>
    </item>
  </channel>
</rss>

