A recent vulnerability discovered in Palo Alto Networks ' PAN-OS has been added to CISA's list of Known Exploitable Vulnerabilities , that is, vulnerabilities that are known to be used in attacks .

This is a high severity vulnerability and is known as CVE-2022-0028. The vulnerability in PAN-OS allows an attacker to remotely launch attacks , without requiring authentication.
See also: Hackers steal crypto due to zero-day vulnerability in Bitcoin ATM
Conditions
Several PAN-OS versions that power PA-Series, VM-Series, and CN-Series devices are vulnerable to CVE-2022-0028. Palo Alto Networks has released patches for all of these versions.
- PAN-OS 10.2 (version < 10.2.2-h2)
- PAN-OS 10.1 (version < 10.1.6-h6)
- PAN-OS 10.0 (version < 10.0.11-h1)
- PAN-OS 9.1 (version < 9.1.14-h4)
- PAN-OS 9.0 (version < 9.0.16-h3) and
- PAN-OS 8.1 (version < 8.1.23-h1)
While exploiting the vulnerability can only cause a DoS condition on the affected device, it has already been used for at least one attack.
See also: Father sent naked photo of son to doctor. Charged with child pornography
In a security advisory published on August 12, Palo Alto Networks says it was made aware of the issue after receiving a notification about an attempted reflected denial-of-service (RDoS) attack through one of products .
According to the company itself, an attacker exploiting the vulnerability in question could hide their original IP address, making recovery more difficult.
CISA is warning federal agencies that they should implement available fixes by September 9th.
See also: WordPress: Fake Cloudflare notifications are distributing malware

However, Palo Alto Networks states that CVE-2022-0028 can only be used for attacks under certain conditions, which are not part of a common firewall configuration:
- The security policy on the firewall that allows traffic from Zone A to Zone B includes a URL filtering profile with one or more blocked categories
- Packet-based attack protection is not enabled in a Zone Protection profile for Zone A, including both (Packet Based Attack Protection > TCP Drop > TCP Syn With Data) and (Packet Based Attack Protection > TCP Drop > Strip TCP Options > TCP Fast Open)
- Flood protection via SYN cookies is not enabled in a Zone Protection profile for Zone A (Flood Protection > SYN > Action > SYN Cookie) with an activation threshold of 0 connections
If organizations with vulnerable devices cannot immediately apply the latest updates, they can use the following guide from Palo Alto Networks as a workaround until fixes are installed.
Source: www.bleepingcomputer.com
