<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PANOS 10.0.6 in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/panos-10-0-6/m-p/426137#M94445</link>
    <description>&lt;P&gt;Is that text from the same PANOS Issue ID (&lt;SPAN&gt;154433) ? From the summary it sounds as if the user-id agent has not been enabled on the firewall you have nothing to worry about.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;cheers,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Seb.&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 11 Aug 2021 13:57:05 GMT</pubDate>
    <dc:creator>SebRupik</dc:creator>
    <dc:date>2021-08-11T13:57:05Z</dc:date>
    <item>
      <title>PANOS 10.0.6</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/panos-10-0-6/m-p/426107#M94437</link>
      <description>&lt;P&gt;Hello, team One of my client want to know the stable version of PANOS there current one is 9.1.5 I suggested them with min apps threat Global protect user-id version and suggest the PANOS 10.0.6 After that the client send me the issue below. The PANOS 10.0.7 is under Monitoring please let me if there is any solution for this.&amp;nbsp;PAN-154433 issue id&lt;/P&gt;&lt;P&gt;PA-820 HA.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Priority 1&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Impact&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Loss of Availability&lt;BR /&gt;Loss of Confidentiality&lt;BR /&gt;Loss of Integrity&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Description&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Palo Alto Networks PAN-OS contains an overflow condition related to the useridd process that is triggered as certain input is not properly validated. This may allow an attacker to cause a buffer overflow, resulting in a denial of service or potentially allowing the execution of arbitrary code.&lt;BR /&gt;&lt;BR /&gt;Palo Alto Networks PAN-OS contains a flaw in the GTP-U that is triggered as the firewall cannot properly detect end-user IP address spoofing when using an IPv6 address. This may allow a remote attacker to bypass firewall protection mechanisms.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Affected Versions&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Palo Alto Networks -&amp;gt; PAN-OS -&amp;gt; 10.0.6&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Fixed Versions&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Palo Alto Networks -&amp;gt; PAN-OS -&amp;gt; 10.0.7&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Solution&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Update to a fixed version.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Reference&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/10-0/pan-os-release-notes/pan-os-10-0-addressed-issues/pan-os-10-0-7-addressed-issues.html#panos-addressed-issues-10.0.7" target="_blank" rel="noopener"&gt;https://docs.paloaltonetworks.com/pan-os/10-0/pan-os-release-notes/pan-os-10-0-addressed-issues/pan-os-10-0-7-addressed-issues.html#panos-addressed-issues-10.0.7&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 11 Aug 2021 13:09:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/panos-10-0-6/m-p/426107#M94437</guid>
      <dc:creator>FarhanKoujalgi</dc:creator>
      <dc:date>2021-08-11T13:09:13Z</dc:date>
    </item>
    <item>
      <title>Re: PANOS 10.0.6</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/panos-10-0-6/m-p/426113#M94438</link>
      <description>&lt;P&gt;Hi there,&lt;/P&gt;&lt;P&gt;Are there any features that you require in your deployment that are only available in the 10.0.x release? If not, then you are probably better off using the preferred 9.1.10 release.&lt;/P&gt;&lt;P&gt;If there are features that require moving to the 10.0.x release, the next question is are you supporting IPv6? If not, then you have a valid mitigation for this vulnerability.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;cheers,&lt;/P&gt;&lt;P&gt;Seb.&lt;/P&gt;</description>
      <pubDate>Wed, 11 Aug 2021 11:57:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/panos-10-0-6/m-p/426113#M94438</guid>
      <dc:creator>SebRupik</dc:creator>
      <dc:date>2021-08-11T11:57:15Z</dc:date>
    </item>
    <item>
      <title>Re: PANOS 10.0.6</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/panos-10-0-6/m-p/426128#M94442</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/143315"&gt;@SebRupik&lt;/a&gt;&amp;nbsp;is absolutely right. If you do not need any features from 10.0 then I recommend to wait at least until x.y.8 or even x.y.9 release. Prior to that I normally don't even consider upgrading to the next version. I had too many problems in the past when I upgraded production firewalls prior to these minor versions. Of course it always depends on which features you use but in general the risk of hitting a bug isn't worth it unless you really need a new feature.&lt;/P&gt;&lt;P&gt;(If you have a lab environment where you can test everything - and I really mean everything with not only 1 or 2 users, then you should be able to reduce the risk of problems)&lt;/P&gt;</description>
      <pubDate>Wed, 11 Aug 2021 12:51:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/panos-10-0-6/m-p/426128#M94442</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2021-08-11T12:51:18Z</dc:date>
    </item>
    <item>
      <title>Re: PANOS 10.0.6</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/panos-10-0-6/m-p/426135#M94444</link>
      <description>&lt;P&gt;&lt;A href="mailto:Thankyou@Sebrupik" target="_blank"&gt;Thankyou@Sebrupik&lt;/A&gt;&lt;/P&gt;&lt;P&gt;what about&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Palo Alto Networks PAN-OS contains an overflow condition related to the useridd process that is triggered as certain input is not properly validated. This may allow an attacker to cause a buffer overflow, resulting in a denial of service or potentially allowing the execution of arbitrary code.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;It is based on when the User id agent is Configured right?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 11 Aug 2021 13:27:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/panos-10-0-6/m-p/426135#M94444</guid>
      <dc:creator>FarhanKoujalgi</dc:creator>
      <dc:date>2021-08-11T13:27:53Z</dc:date>
    </item>
    <item>
      <title>Re: PANOS 10.0.6</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/panos-10-0-6/m-p/426137#M94445</link>
      <description>&lt;P&gt;Is that text from the same PANOS Issue ID (&lt;SPAN&gt;154433) ? From the summary it sounds as if the user-id agent has not been enabled on the firewall you have nothing to worry about.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;cheers,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Seb.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 11 Aug 2021 13:57:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/panos-10-0-6/m-p/426137#M94445</guid>
      <dc:creator>SebRupik</dc:creator>
      <dc:date>2021-08-11T13:57:05Z</dc:date>
    </item>
    <item>
      <title>Re: PANOS 10.0.6</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/panos-10-0-6/m-p/426139#M94447</link>
      <description>&lt;DIV&gt;PAN-158372&lt;/DIV&gt;&lt;P&gt;&lt;SPAN&gt;Fixed a buffer overflow issue related to the user id&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;process.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;No, this text is from another PANOS issue id&amp;nbsp;&lt;/P&gt;&lt;P&gt;So for this issue, if the user -id agent has not been enabled on the firewall we have nothing to worry about right?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 11 Aug 2021 14:08:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/panos-10-0-6/m-p/426139#M94447</guid>
      <dc:creator>FarhanKoujalgi</dc:creator>
      <dc:date>2021-08-11T14:08:14Z</dc:date>
    </item>
    <item>
      <title>Re: PANOS 10.0.6</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/panos-10-0-6/m-p/426140#M94448</link>
      <description>&lt;P&gt;Exactly, most of the unresolved issues on a release can be mitigated by the fact a particular feature is not part of the running config.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;cheers,&lt;/P&gt;&lt;P&gt;Seb.&lt;/P&gt;</description>
      <pubDate>Wed, 11 Aug 2021 14:14:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/panos-10-0-6/m-p/426140#M94448</guid>
      <dc:creator>SebRupik</dc:creator>
      <dc:date>2021-08-11T14:14:28Z</dc:date>
    </item>
  </channel>
</rss>

