DNS Server Cache Snooping Remote Information Disclosure

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

DNS Server Cache Snooping Remote Information Disclosure

L4 Transporter
We require our network to be PCI DSS compliant, and our most recent vulnerability scan showed a "DNS Server Cache Snooping Remote Information Disclosure" vulnerability on our PA-820 data interface (10.32.0.17) (report below)
dnsserversnooping.jpg
We are using model 820 in PANOS 8.1.15. All Dynamic contents are up to date.

Threat log showing:

1 15/12/2020 14:21 0002324375 THREAT vulnerability 2049 15/12/2020 14:21 10.32.15.215 10.32.0.17 AzureTemp-IN HR ms-ds-smbv3 vsys1 VPN-RAS Internal tunnel.3 ethernet1/4 15/12/2020 14:21 37955 1 32962 445 0 0 0x2000 tcp alert Windows Local Security Architect LsarQueryInformationPolicy(30858) any informational client-to-server 11164322 0x2000 10.0.0.0-10.255.255.255 10.0.0.0-10.255.255.255 0 0 0 0 0 0 0 0 pa-820 0 0 N/A info-leak AppThreat-8353-6449 0x0 0 4294967295

 

Could you please advise how to close this vulnerability?
1 accepted solution

Accepted Solutions

Cyber Elite
Cyber Elite

This is not really a vulnerability but rather a configurtion option that should not be accessible from the outside: this event is typically triggered if a DNS server allows for recursion while it is reachable from the outside

 

a fix is to either set an access list on the DNS server so only internal hosts are allowed to use recursion, disable recursion completely, or make the DNS server inaccessible from the outside

Tom Piens
PANgurus - Strata specialist; config reviews, policy optimization

View solution in original post

1 REPLY 1

Cyber Elite
Cyber Elite

This is not really a vulnerability but rather a configurtion option that should not be accessible from the outside: this event is typically triggered if a DNS server allows for recursion while it is reachable from the outside

 

a fix is to either set an access list on the DNS server so only internal hosts are allowed to use recursion, disable recursion completely, or make the DNS server inaccessible from the outside

Tom Piens
PANgurus - Strata specialist; config reviews, policy optimization
  • 1 accepted solution
  • 4800 Views
  • 1 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!