Enabling signatures in content update version 8317

cancel
Showing results for 
Search instead for 
Did you mean: 

Enabling signatures in content update version 8317

L0 Member

Checking CVE-2020-2040 it says "Until PAN-OS software is upgraded to a fixed version, enabling signatures in content update version 8317 will block attacks against CVE-2020-2040.", and I'm not sure what does "enabling signatures in content update version 8317" mean and can't find anything online about it. 

5 REPLIES 5

Cyber Elite
Cyber Elite

Hello,

Interesting question. I would think that they mean to say install the signatures and make sure they are applied to a security policy?

Regards,

L2 Linker

Hello @Raydar 

In content version 8317 we released 4 new vulnerability signatures (UTIDs 59270, 59255, 59259, 59267) to provide coverage against CVE-2020-2040; so until you upgrade PAN-OS, you can enforce the traffic with a security policy with a Vulnerability Protection Profile and this will help to deter any potential attempt of exploitation of this vulnerability. 

L1 Bithead

Enable the No auto-restart for scheduled Automatic Updates installations parameter.  Bypass Approval permission to this role and adding the relevant content sets.  Windows OS Major Version > 6.0 and Tanium Client Version >= 7.2.314.3211  and Repo GPG Check to confirm authenticity by verifying GPG signatures.

L0 Member

Always review Content Release Notes for the list of newly-identified and modified application and threat signatures that the content release introduces. Content Release Notes also describe how the update might impact existing security policy enforcement and provides recommendations on how you can modify your security policy to best leverage what’s new.

L0 Member
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!