- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
11-16-2023 01:06 AM
Hi Support,
Recently we have Vulnerability Assessment and found two vulnerability on Panorama
1. “The remote HTTPS server is not enforcing HTTP Strict Transport Security (HSTS) on Port 28443
2.“SSL Certificate Cannot Be Trusted” for port 28270.
How can we remediate on both vulnerability above?
Any advise and solution much appreciated
Thank you
Regards
Fariq
08-05-2024 03:50 PM
Hello @Fariq_Zaidi
the issue you described has own KB: A vulnerability "HSTS Missing From HTTPS Server" is reported on Panorama on port TCP/28443.
Kind Regards
Pavel
11-20-2023 07:57 PM
Hello @Fariq_Zaidi
Port 28443 is specifically utilized for downloading content files from Panorama by firewalls. On the other hand, port 28270 is employed for communication between Panorama and managed firewalls or managed collectors.
It's important to note that these ports facilitate communication between Palo Alto devices and proper certificate validations are enforced in this communication. The certificates involved can be self-signed. Consequently, the alerts you are observing could be triggered by external tools attempting connection or checks, which may not fully validate the certificates in use.
08-05-2024 03:50 PM
Hello @Fariq_Zaidi
the issue you described has own KB: A vulnerability "HSTS Missing From HTTPS Server" is reported on Panorama on port TCP/28443.
Kind Regards
Pavel
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!