CVE-2022-0028
Palo Alto Networks PAN-OS: Reflected Amplification Denial-of-Service
As of , CVE-2022-0028 in Palo Alto Networks PAN-OS is on CISA's list of exploited vulnerabilities: CISA listed it on . Our patch-first group: Patch soon.
- Exploited
- Yes: CISA listed it on 22 August 2022
- US federal deadline
- 12 September 202221 days after CISA listed it. US federal civilian agencies must fix it by then.
- Used in ransomware campaigns
- Not known to CISA
- EPSS score
- 0.03Higher than 84% of the CVEs EPSS scores. EPSS estimates the chance of exploitation activity in the next 30 days.
- EPSS when listed
- 0.01 on 22 August 2022EPSS on the day CISA listed it.
- Public exploit
- None foundNeither Metasploit nor Exploit-DB lists one.
- Fix
- Vendor advice: security.paloaltonetworks.comLinks below, from CISA's entry.
What CISA says to do
Apply updates per vendor instructions.
CISA's required action
What the flaw is
A Palo Alto Networks PAN-OS URL filtering policy misconfiguration could allow a network-based attacker to conduct reflected and amplified TCP denial-of-service (RDoS) attacks.
CISA's description
A PAN-OS URL filtering policy misconfiguration could allow a network-based attacker to conduct reflected and amplified TCP denial-of-service (RDoS) attacks. The DoS attack would appear to originate from a Palo Alto Networks PA-Series (hardware), VM-Series (virtual) and CN-Series (container) firewall against an attacker-specified target. To be misused by an external attacker, the firewall configuration must have a URL filtering profile with one or more blocked categories assigned to a source zone that has an external facing interface. This configuration is not typical for URL filtering and, if set, is likely unintended by the administrator. If exploited, this issue would not impact the confidentiality, integrity, or availability of our products. However, the resulting denial-of-service (DoS) attack may help obfuscate the identity of the attacker and implicate the firewall as the source of the attack. We have taken prompt action to address this issue in our PAN-OS software. All software updates for this issue are expected to be released no later than the week of August 15, 2022. This issue does not impact Panorama M-Series or Panorama virtual appliances. This issue has been resolved for all Cloud NGFW and Prisma Access customers and no additional action is required from them.
The CVE record's description, from palo_alto
- CVE published
- 10 August 2022
- Assigned by
- palo_alto
- CVSS
- 8.6 High (CVSS 3.1, from the CNA)
- CWE-406
- Insufficient Control of Network Message Volume (Network Amplification)
- CWE-940
- Improper Verification of Source of a Communication Channel
- CISA SSVC, exploitation
- active
- CISA SSVC, automatable
- yes
- CISA SSVC, technical impact
- partial
Timeline
- The CVE record was published.
- CISA added it to its list of exploited vulnerabilities.
- The US federal deadline to fix it.
PAN-OS: other exploited entries
| Vulnerability | Product | Our group | Listed | Deadline | EPSS |
|---|---|---|---|---|---|
| CVE-2026-0257Authentication Bypass | Palo Alto Networks PAN-OS | Patch nowRansomware use, listed within a year | 0.97 | ||
| CVE-2017-15944Remote Code Execution | Palo Alto Networks PAN-OS | Patch this weekMetasploit module; EPSS 0.98; verified Exploit-DB entry | 0.98 | ||
| CVE-2024-0012Management Interface Authentication Bypass | Palo Alto Networks PAN-OS | Patch this weekRansomware use; Metasploit module; EPSS 0.99 | 0.99 | ||
| CVE-2024-9474Management Interface OS Command Injection | Palo Alto Networks PAN-OS | Patch this weekRansomware use; Metasploit module; EPSS 0.95 | 0.95 | ||
| CVE-2024-3400Command Injection | Palo Alto Networks PAN-OS | Patch this weekRansomware use; Metasploit module; EPSS 0.99 | 0.99 | ||
| CVE-2025-0108Authentication Bypass | Palo Alto Networks PAN-OS | Patch this weekEPSS 0.98 | 0.98 | ||
| CVE-2019-1579Remote Code Execution | Palo Alto Networks PAN-OS | Patch this weekRansomware use | 0.46 | ||
| CVE-2020-2021Authentication Bypass | Palo Alto Networks PAN-OS | Patch this weekRansomware use | 0.04 | ||
| CVE-2026-0300Out-of-bounds Write | Palo Alto Networks PAN-OS | Patch soon | 0.32 | ||
| CVE-2024-3393Malicious DNS Packet | Palo Alto Networks PAN-OS | Patch soon | 0.29 |
Read further
- CVE recordcve.org
- NVD entrynvd.nist.gov
- CISA's catalogcisa.gov
- EPSS for this CVEapi.first.org