- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
Enhanced Security Measures in Place: To ensure a safer experience, we’ve implemented additional, temporary security measures for all users.
10-05-2022 11:48 PM
Hi all,
I wanted to ask CVE-2022-0028 Pan-os:Reflected amplification dow vulnerability in URL filtering Will still affect my environment if i am using separate PROXY SERVER(Forcepoint proxy) for url filtering purpose?
Palo alto url filtering is used but its for specific policies rather all other traffic use forcepoint proxy for URL filtering...
10-10-2022 04:16 AM
Hi @Kashif_shaikh ,
As mentioned in the official security advisory - https://security.paloaltonetworks.com/CVE-2022-0028 if you use URL Filtering profile with at least one category set to block in your rules, your firewall is exploitable.
BUT
As mentioned in the link the risk is drasticly lowered if you don't have URL filtering profile on inbound rule.
If you have URL profile enabled only on rules for outbound traffic (from inside to internet), the risk of potential explotation is lower, but still there is a chance of insider threat. If you want to completely eliminate the risk you can follow the suggested workaround and enable the zone protection profile for the inside zone
10-10-2022 04:16 AM
Hi @Kashif_shaikh ,
As mentioned in the official security advisory - https://security.paloaltonetworks.com/CVE-2022-0028 if you use URL Filtering profile with at least one category set to block in your rules, your firewall is exploitable.
BUT
As mentioned in the link the risk is drasticly lowered if you don't have URL filtering profile on inbound rule.
If you have URL profile enabled only on rules for outbound traffic (from inside to internet), the risk of potential explotation is lower, but still there is a chance of insider threat. If you want to completely eliminate the risk you can follow the suggested workaround and enable the zone protection profile for the inside zone
10-18-2022 11:16 AM
Thanks @aleksandar.astardzhiev
12-22-2022 07:15 AM
Thanks for the solution.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!