« Volver al listado

CVE-2022-0028

Estado: AnalizadaAlta (8.6)⚠ Explotación activa

A PAN-OS URL filtering policy misconfiguration could allow a network-based attacker to conduct reflected and amplified TCP denial-of-service (RDoS) attacks. The DoS attack would appear to originate from a Palo Alto Networks PA-Series (hardware), VM-Series (virtual) and CN-Series (container) firewall against an attacker-specified target. To be misused by an external attacker, the firewall configuration must have a URL filtering profile with one or more blocked categories assigned to a source zone that has an external facing interface.

Leer descripción completaMostrar menos

This configuration is not typical for URL filtering and, if set, is likely unintended by the administrator. If exploited, this issue would not impact the confidentiality, integrity, or availability of our products. However, the resulting denial-of-service (DoS) attack may help obfuscate the identity of the attacker and implicate the firewall as the source of the attack. We have taken prompt action to address this issue in our PAN-OS software. All software updates for this issue are expected to be released no later than the week of August 15, 2022. This issue does not impact Panorama M-Series or Panorama virtual appliances. This issue has been resolved for all Cloud NGFW and Prisma Access customers and no additional action is required from them.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

CISA KEV — explotada activamente

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

CVE permite explotación remota sin autenticación (AV:N, PR:N, UI:N) de misconfigración de firewall Palo Alto para lanzar ataques RDoS amplificados contra objetivos especificados, generando DoS (CVSS A:H).

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2022-0028",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2022-0028",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "active"
            },
            {
              "automatable": "yes"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2025-01-27T22:26:35.523479Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "psirt@paloaltonetworks.com",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 8.6,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 4,
        "exploitabilityScore": 3.9
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 8.6,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 4,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "psirt@paloaltonetworks.com",
      "affectedData": [
        {
          "vendor": "Palo Alto Networks",
          "product": "Cloud NGFW",
          "versions": [
            {
              "status": "unaffected",
              "version": "All"
            }
          ]
        },
        {
          "vendor": "Palo Alto Networks",
          "product": "PAN-OS",
          "versions": [
            {
              "status": "affected",
              "changes": [
                {
                  "at": "8.1.23-h1",
                  "status": "unaffected"
                }
              ],
              "version": "8.1",
              "lessThan": "8.1.23-h1",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "changes": [
                {
                  "at": "9.0.16-h3",
                  "status": "unaffected"
                }
              ],
              "version": "9.0",
              "lessThan": "9.0.16-h3",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "changes": [
                {
                  "at": "9.1.14-h4",
                  "status": "unaffected"
                }
              ],
              "version": "9.1",
              "lessThan": "9.1.14-h4",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "changes": [
                {
                  "at": "10.0.11-h1",
                  "status": "unaffected"
                }
              ],
              "version": "10.0",
              "lessThan": "10.0.11-h1",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "changes": [
                {
                  "at": "10.1.6-h6",
                  "status": "unaffected"
                }
              ],
              "version": "10.1",
              "lessThan": "10.1.6-h6",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "changes": [
                {
                  "at": "10.2.2-h2",
                  "status": "unaffected"
                }
              ],
              "version": "10.2",
              "lessThan": "10.2.2-h2",
              "versionType": "custom"
            }
          ]
        },
        {
          "vendor": "Palo Alto Networks",
          "product": "Prisma Access",
          "versions": [
            {
              "status": "unaffected",
              "version": "2.1 All"
            },
            {
              "status": "unaffected",
              "version": "2.2 All"
            },
            {
              "status": "unaffected",
              "version": "3.0 All"
            },
            {
              "status": "unaffected",
              "version": "3.1 All"
            }
          ]
        }
      ]
    },
    {
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
      "affectedData": [
        {
          "cpes": [
            "cpe:2.3:o:paloaltonetworks:pan-os:8.1.0:*:*:*:*:*:*:*"
          ],
          "vendor": "paloaltonetworks",
          "product": "pan-os",
          "versions": [
            {
              "status": "affected",
              "version": "8.1.0",
              "lessThan": "8.1.23-h",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "unknown"
        },
        {
          "cpes": [
            "cpe:2.3:o:paloaltonetworks:pan-os:9.0.0:*:*:*:*:*:*:*"
          ],
          "vendor": "paloaltonetworks",
          "product": "pan-os",
          "versions": [
            {
              "status": "affected",
              "version": "9.0.0",
              "lessThan": "9.0.16-h3",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "unknown"
        },
        {
          "cpes": [
            "cpe:2.3:o:paloaltonetworks:pan-os:9.1.0:*:*:*:*:*:*:*"
          ],
          "vendor": "paloaltonetworks",
          "product": "pan-os",
          "versions": [
            {
              "status": "affected",
              "version": "9.1.0",
              "lessThan": "9.1 < 9.1.14-h4",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "unknown"
        },
        {
          "cpes": [
            "cpe:2.3:o:paloaltonetworks:pan-os:10.0.0:*:*:*:*:*:*:*"
          ],
          "vendor": "paloaltonetworks",
          "product": "pan-os",
          "versions": [
            {
              "status": "affected",
              "version": "10.0.0",
              "lessThan": "10.0.11-h1",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "unknown"
        },
        {
          "cpes": [
            "cpe:2.3:o:paloaltonetworks:pan-os:10.1.0:*:*:*:*:*:*:*"
          ],
          "vendor": "paloaltonetworks",
          "product": "pan-os",
          "versions": [
            {
              "status": "affected",
              "version": "10.1.0",
              "lessThan": "10.1.6-h6",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "unknown"
        },
        {
          "cpes": [
            "cpe:2.3:o:paloaltonetworks:pan-os:10.2.0:*:*:*:*:*:*:*"
          ],
          "vendor": "paloaltonetworks",
          "product": "pan-os",
          "versions": [
            {
              "status": "affected",
              "version": "10.2.0",
              "lessThan": "10.2.2-h2",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "unknown"
        }
      ]
    }
  ],
  "published": "2022-08-10T16:15:08.343",
  "references": [
    {
      "url": "https://security.paloaltonetworks.com/CVE-2022-0028",
      "tags": [
        "Mitigation",
        "Third Party Advisory"
      ],
      "source": "psirt@paloaltonetworks.com"
    },
    {
      "url": "https://security.paloaltonetworks.com/CVE-2022-0028",
      "tags": [
        "Mitigation",
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-0028",
      "tags": [
        "US Government Resource"
      ],
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "psirt@paloaltonetworks.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-406"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-Other"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "A PAN-OS URL filtering policy misconfiguration could allow a network-based attacker to conduct reflected and amplified TCP denial-of-service (RDoS) attacks. The DoS attack would appear to originate from a Palo Alto Networks PA-Series (hardware), VM-Series (virtual) and CN-Series (container) firewall against an attacker-specified target. To be misused by an external attacker, the firewall configuration must have a URL filtering profile with one or more blocked categories assigned to a source zone that has an external facing interface. This configuration is not typical for URL filtering and, if set, is likely unintended by the administrator. If exploited, this issue would not impact the confidentiality, integrity, or availability of our products. However, the resulting denial-of-service (DoS) attack may help obfuscate the identity of the attacker and implicate the firewall as the source of the attack. We have taken prompt action to address this issue in our PAN-OS software. All software updates for this issue are expected to be released no later than the week of August 15, 2022. This issue does not impact Panorama M-Series or Panorama virtual appliances. This issue has been resolved for all Cloud NGFW and Prisma Access customers and no additional action is required from them."
    },
    {
      "lang": "es",
      "value": "Una mala configuración de la política de filtrado de URL de PAN-OS podría permitir a un atacante basado en la red conducir ataques de denegación de servicio TCP reflejados y amplificados (RDoS). El ataque de denegación de servicio parecería originarse desde un firewall de la serie PA (hardware), la serie VM (virtual) y la serie CN (contenedor) de Palo Alto Networks contra un objetivo especificado por el atacante. Para que un atacante externo haga un uso no debido, la configuración del firewall debe tener un perfil de filtrado de URL con una o más categorías bloqueadas asignadas a una zona de origen que tenga una interfaz de cara al exterior. Esta configuración no es típica para el filtrado de URL y, si es establecido, es probable que no sea intencionada por el administrador. Si es explotado, este problema no afectaría a la confidencialidad, integridad o disponibilidad de nuestros productos. Sin embargo, el ataque de denegación de servicio (DoS) resultando puede ayudar a ofuscar la identidad del atacante e implicar al firewall como la fuente del ataque. Hemos tomado medidas rápidas para abordar este problema en nuestro software PAN-OS. Es esperado que todas las actualizaciones de software para este problema sean publicadas a más tardar en la semana del 15 de agosto de 2022. Este problema no afecta a dispositivos virtuales de Panorama M-Series o Panorama. Este problema ha sido resuelto para todos los clientes de Cloud NGFW y Prisma Access y no es requerida ninguna acción adicional por su parte"
    }
  ],
  "lastModified": "2026-06-17T04:19:55.243",
  "cisaActionDue": "2022-09-12",
  "cisaExploitAdd": "2022-08-22",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:paloaltonetworks:pan-os:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "99EC0B3A-A8BE-4394-81F0-C05BA177F867",
              "versionEndExcluding": "8.1.23",
              "versionStartIncluding": "8.1.0"
            },
            {
              "criteria": "cpe:2.3:o:paloaltonetworks:pan-os:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0E3757E3-17C0-4D42-A31A-78F40A774F41",
              "versionEndExcluding": "9.0.16",
              "versionStartIncluding": "9.0.0"
            },
            {
              "criteria": "cpe:2.3:o:paloaltonetworks:pan-os:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D457521C-1D9D-46C2-A1EE-3999A1F054A1",
              "versionEndExcluding": "9.1.14",
              "versionStartIncluding": "9.1.0"
            },
            {
              "criteria": "cpe:2.3:o:paloaltonetworks:pan-os:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "30D919C6-068E-4C81-A7A7-261F0D9E4B66",
              "versionEndExcluding": "10.0.11",
              "versionStartIncluding": "10.0.0"
            },
            {
              "criteria": "cpe:2.3:o:paloaltonetworks:pan-os:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E6EB81D3-ADC7-4114-8FFB-C15780239391",
              "versionEndExcluding": "10.1.6",
              "versionStartIncluding": "10.1.0"
            },
            {
              "criteria": "cpe:2.3:o:paloaltonetworks:pan-os:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "22513B1B-6022-4732-8CD4-6E74E40D664A",
              "versionEndExcluding": "10.2.2",
              "versionStartIncluding": "10.2.0"
            },
            {
              "criteria": "cpe:2.3:o:paloaltonetworks:pan-os:8.1.23:-:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2377E54D-3B6F-4DA3-9A82-355AAFA26BC1"
            },
            {
              "criteria": "cpe:2.3:o:paloaltonetworks:pan-os:9.0.16:-:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C099A5E1-849D-4A3B-B780-C994EFFC6783"
            },
            {
              "criteria": "cpe:2.3:o:paloaltonetworks:pan-os:9.0.16:h2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7BB17CCF-BE75-4B23-91C5-397BE25C1DC7"
            },
            {
              "criteria": "cpe:2.3:o:paloaltonetworks:pan-os:9.1.14:-:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "39BA8B04-A3A5-4636-867C-C6BB3F24C3B6"
            },
            {
              "criteria": "cpe:2.3:o:paloaltonetworks:pan-os:9.1.14:h1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "431E508F-3A80-4146-B88E-CEBA0AB5A850"
            },
            {
              "criteria": "cpe:2.3:o:paloaltonetworks:pan-os:10.0.11:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "142E4A38-662F-4DF9-9E0E-4B9BB9A78F7F"
            },
            {
              "criteria": "cpe:2.3:o:paloaltonetworks:pan-os:10.1.6:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "443462D5-461E-46A0-80E6-61CF30D4D71F"
            },
            {
              "criteria": "cpe:2.3:o:paloaltonetworks:pan-os:10.1.6:h3:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "299A820D-E4E7-40FA-A4C2-6F1699E13DFA"
            },
            {
              "criteria": "cpe:2.3:o:paloaltonetworks:pan-os:10.2.2:-:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "33340036-0E81-41CD-AFC4-480F509F8DD2"
            },
            {
              "criteria": "cpe:2.3:o:paloaltonetworks:pan-os:10.2.2:h1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5D7986DC-187D-4798-8B4A-7D23DF0EE0C8"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "psirt@paloaltonetworks.com",
  "cisaRequiredAction": "Apply updates per vendor instructions.",
  "cisaVulnerabilityName": "Palo Alto Networks PAN-OS Reflected Amplification Denial-of-Service Vulnerability"
}