Enhanced Security Measures in Place:   To ensure a safer experience, we’ve implemented additional, temporary security measures for all users.

CVE-2022-00028

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

CVE-2022-00028

L1 Bithead

Hi all,

 

I wanted to ask CVE-2022-0028 Pan-os:Reflected amplification dow vulnerability in URL filtering Will still affect my environment if i am using separate PROXY SERVER(Forcepoint proxy) for url filtering purpose? 

 

Palo alto url filtering is used but its for specific policies rather all other traffic use forcepoint proxy for URL filtering... 

kashif shaikh
1 accepted solution

Accepted Solutions

Hi @Kashif_shaikh ,

As mentioned in the official security advisory - https://security.paloaltonetworks.com/CVE-2022-0028 if you use URL Filtering profile with at least one category set to block in your rules, your firewall is exploitable.

BUT

 

As mentioned in the link the risk is drasticly lowered if you don't have URL filtering profile on inbound rule.

If you have URL profile enabled only on rules for outbound traffic (from inside to internet), the risk of potential explotation is lower, but still there is a chance of insider threat. If you want to completely eliminate the risk you can follow the suggested workaround and enable the zone protection profile for the inside zone

View solution in original post

3 REPLIES 3

Hi @Kashif_shaikh ,

As mentioned in the official security advisory - https://security.paloaltonetworks.com/CVE-2022-0028 if you use URL Filtering profile with at least one category set to block in your rules, your firewall is exploitable.

BUT

 

As mentioned in the link the risk is drasticly lowered if you don't have URL filtering profile on inbound rule.

If you have URL profile enabled only on rules for outbound traffic (from inside to internet), the risk of potential explotation is lower, but still there is a chance of insider threat. If you want to completely eliminate the risk you can follow the suggested workaround and enable the zone protection profile for the inside zone

L1 Bithead

Thanks @aleksandar.astardzhiev 

kashif shaikh

L0 Member

Thanks for the solution.

Thanks for the solution. I found your post mistakenly because I was searching for a site online where I can find new zealand casinos sites and when I was looking for it online, I found your post as well.
  • 1 accepted solution
  • 2667 Views
  • 3 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!