Palo Alto Vulnerability Points (Urgent Action Required)

Reply
Highlighted
L3 Networker

Palo Alto Vulnerability Points (Urgent Action Required)

Hi Team,

 

Can anyone provide your valuable suggestion here please.

Below are the VAPT points shared by customer and solution provided :

 

PA Vulnerability points (For reference please find attached pdf) :
1) ssl/tls protocol initialization vector implementation information disclosure vulnerability (BEAST) - SSL/tls profile needs to be configure for firewall mgmt access. SSL/TLS version we can keep from TLS1.1 to TLS 1.2
2) ssl/tls protocol initialization vector implementation information disclosure vulnerability (BEAST) - SSL/tls profile needs to be configure for firewall mgmt access. SSL/TLS version we can keep from TLS1.1 to TLS 1.2
3) SSL self-signed certificate - Purchase a certificate
4) ssl certificate cannot be trusted - Purchase a certificate
5) ssl certificate cannot be trusted - Purchase a certificate
6) SSL medium strength cipher suites supported(sweet32) - ECDSA certificate configure in Firewall
7) SSL certificate siged using weak hashing algorithm - ECDSA certificate configure in Firewall
8) SSH weak algorithm supported - enable only GCM and CTR ciphers , only applicable above 8.0 version
9) HSTS missing from HTTPS server - Need to check with tac
10) HSTS missing from HTTPS server - Need to check with tac
11) HTTP Methos allowed (per directory) - Need to check with tac
12) HTTP Methos allowed (per directory) - Need to check with tac
13) SSH server CBC mode ciphers enabled - enable only GCM and CTR ciphers , only applicable above 8.0 version
14) SSH weak mac algorithm enabled - we can disable ssh weak mac algorithm , only applicable above 8.0 version

 

Please correct if anything wrong.

 

Software Version 7.1.21
Model PA-500

 

Please help us here to provide solution of following questions if anyone knows,

 

9) HSTS missing from HTTPS server - ?
10) HSTS missing from HTTPS server - ?
11) HTTP Methos allowed (per directory) - ?
12) HTTP Methos allowed (per directory) - ?

 

 

Regards,

Sethupathi M

Community Manager

Re: Palo Alto Vulnerability Points (Urgent Action Required)

thats 2x the same question ? could you add some more details? If something is missing from the server, you'll want to check the server, same for the http methods allowed per directory

Help the community: Like helpful comments and mark solutions
Reaper out
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!

The Live Community thanks you for your participation!