Palo Alto Vulnerability Points (Urgent Action Required)

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

Palo Alto Vulnerability Points (Urgent Action Required)

L3 Networker

Hi Team,

 

Can anyone provide your valuable suggestion here please.

Below are the VAPT points shared by customer and solution provided :

 

PA Vulnerability points (For reference please find attached pdf) :
1) ssl/tls protocol initialization vector implementation information disclosure vulnerability (BEAST) - SSL/tls profile needs to be configure for firewall mgmt access. SSL/TLS version we can keep from TLS1.1 to TLS 1.2
2) ssl/tls protocol initialization vector implementation information disclosure vulnerability (BEAST) - SSL/tls profile needs to be configure for firewall mgmt access. SSL/TLS version we can keep from TLS1.1 to TLS 1.2
3) SSL self-signed certificate - Purchase a certificate
4) ssl certificate cannot be trusted - Purchase a certificate
5) ssl certificate cannot be trusted - Purchase a certificate
6) SSL medium strength cipher suites supported(sweet32) - ECDSA certificate configure in Firewall
7) SSL certificate siged using weak hashing algorithm - ECDSA certificate configure in Firewall
😎 SSH weak algorithm supported - enable only GCM and CTR ciphers , only applicable above 8.0 version
9) HSTS missing from HTTPS server - Need to check with tac
10) HSTS missing from HTTPS server - Need to check with tac
11) HTTP Methos allowed (per directory) - Need to check with tac
12) HTTP Methos allowed (per directory) - Need to check with tac
13) SSH server CBC mode ciphers enabled - enable only GCM and CTR ciphers , only applicable above 8.0 version
14) SSH weak mac algorithm enabled - we can disable ssh weak mac algorithm , only applicable above 8.0 version

 

Please correct if anything wrong.

 

Software Version 7.1.21
Model PA-500

 

Please help us here to provide solution of following questions if anyone knows,

 

9) HSTS missing from HTTPS server - ?
10) HSTS missing from HTTPS server - ?
11) HTTP Methos allowed (per directory) - ?
12) HTTP Methos allowed (per directory) - ?

 

 

Regards,

Sethupathi M

1 REPLY 1

Cyber Elite
Cyber Elite
thats 2x the same question ? could you add some more details? If something is missing from the server, you'll want to check the server, same for the http methods allowed per directory
Tom Piens
PANgurus - Strata specialist; config reviews, policy optimization
  • 3325 Views
  • 1 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!