We have enabled ssl inbound decryption and able to exploit the vulnerabilty

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

We have enabled ssl inbound decryption and able to exploit the vulnerabilty

Cyber Elite
Cyber Elite

 

We have ssl inbound  decryption configured  and from outside we are able to exploit the vulnerabilty.

Need to know why PA allows the connection for that signature.

 

Vul  threat id is 57230

 

Name Telerik Web UI

MP

Help the community: Like helpful comments and mark solutions.
1 accepted solution

Accepted Solutions

Seems Palo Alto did the content upgrade on their end recently and now we see that signature is blocking the traffic.

MP

Help the community: Like helpful comments and mark solutions.

View solution in original post

4 REPLIES 4

L7 Applicator

Sounds like a false negative, but the forum is not the right place to troubleshoot this. Please open a Support case. You will be asked to provide the exploit PoC, a packet capture of the attack (capture it from the client side) and supporting evidence that SSL decryption is working properly (detailed traffic log view showing the decrypted application normally detected and readable by the firewall).

I agree we have opened the case with PA for 10 days as per them decryption is working as expected.

They are looking into this vulnerability as we can exploit the signature.

MP

Help the community: Like helpful comments and mark solutions.

PA is still searching on this.

MP

Help the community: Like helpful comments and mark solutions.

Seems Palo Alto did the content upgrade on their end recently and now we see that signature is blocking the traffic.

MP

Help the community: Like helpful comments and mark solutions.
  • 1 accepted solution
  • 4419 Views
  • 4 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!