We have enabled ssl inbound decryption and able to exploit the vulnerabilty

Reply
Highlighted
Cyber Elite

We have enabled ssl inbound decryption and able to exploit the vulnerabilty

 

We have ssl inbound  decryption configured  and from outside we are able to exploit the vulnerabilty.

Need to know why PA allows the connection for that signature.

 

Vul  threat id is 57230

 

Name Telerik Web UI

MP

Accepted Solutions
Highlighted
Cyber Elite

Re: We have enabled ssl inbound decryption and able to exploit the vulnerab

Seems Palo Alto did the content upgrade on their end recently and now we see that signature is blocking the traffic.

MP

View solution in original post


All Replies
Highlighted
L6 Presenter

Re: We have enabled ssl inbound decryption and able to exploit the vulnerab

Sounds like a false negative, but the forum is not the right place to troubleshoot this. Please open a Support case. You will be asked to provide the exploit PoC, a packet capture of the attack (capture it from the client side) and supporting evidence that SSL decryption is working properly (detailed traffic log view showing the decrypted application normally detected and readable by the firewall).

Highlighted
Cyber Elite

Re: We have enabled ssl inbound decryption and able to exploit the vulnerab

I agree we have opened the case with PA for 10 days as per them decryption is working as expected.

They are looking into this vulnerability as we can exploit the signature.

MP
Highlighted
Cyber Elite

Re: We have enabled ssl inbound decryption and able to exploit the vulnerab

PA is still searching on this.

MP
Highlighted
Cyber Elite

Re: We have enabled ssl inbound decryption and able to exploit the vulnerab

Seems Palo Alto did the content upgrade on their end recently and now we see that signature is blocking the traffic.

MP

View solution in original post

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!

The Live Community thanks you for your participation!