CVE-2022-0028

Palo Alto Networks PAN-OS: Reflected Amplification Denial-of-Service

As of , CVE-2022-0028 in Palo Alto Networks PAN-OS is on CISA's list of exploited vulnerabilities: CISA listed it on . Our patch-first group: Patch soon.

Exploited
Yes: CISA listed it on 22 August 2022
US federal deadline
12 September 202221 days after CISA listed it. US federal civilian agencies must fix it by then.
Used in ransomware campaigns
Not known to CISA
EPSS score
0.03Higher than 84% of the CVEs EPSS scores. EPSS estimates the chance of exploitation activity in the next 30 days.
EPSS when listed
0.01 on 22 August 2022EPSS on the day CISA listed it.
Public exploit
None foundNeither Metasploit nor Exploit-DB lists one.
Fix
Vendor advice: security.paloaltonetworks.comLinks below, from CISA's entry.

What CISA says to do

Apply updates per vendor instructions.

CISA's required action

What the flaw is

A Palo Alto Networks PAN-OS URL filtering policy misconfiguration could allow a network-based attacker to conduct reflected and amplified TCP denial-of-service (RDoS) attacks.

CISA's description

A PAN-OS URL filtering policy misconfiguration could allow a network-based attacker to conduct reflected and amplified TCP denial-of-service (RDoS) attacks. The DoS attack would appear to originate from a Palo Alto Networks PA-Series (hardware), VM-Series (virtual) and CN-Series (container) firewall against an attacker-specified target. To be misused by an external attacker, the firewall configuration must have a URL filtering profile with one or more blocked categories assigned to a source zone that has an external facing interface. This configuration is not typical for URL filtering and, if set, is likely unintended by the administrator. If exploited, this issue would not impact the confidentiality, integrity, or availability of our products. However, the resulting denial-of-service (DoS) attack may help obfuscate the identity of the attacker and implicate the firewall as the source of the attack. We have taken prompt action to address this issue in our PAN-OS software. All software updates for this issue are expected to be released no later than the week of August 15, 2022. This issue does not impact Panorama M-Series or Panorama virtual appliances. This issue has been resolved for all Cloud NGFW and Prisma Access customers and no additional action is required from them.

The CVE record's description, from palo_alto

CVE published
10 August 2022
Assigned by
palo_alto
CVSS
8.6 High (CVSS 3.1, from the CNA)
CWE-406
Insufficient Control of Network Message Volume (Network Amplification)
CWE-940
Improper Verification of Source of a Communication Channel
CISA SSVC, exploitation
active
CISA SSVC, automatable
yes
CISA SSVC, technical impact
partial

Timeline

  1. The CVE record was published.
  2. CISA added it to its list of exploited vulnerabilities.
  3. The US federal deadline to fix it.

PAN-OS: other exploited entries

VulnerabilityProductOur groupListedDeadlineEPSS
CVE-2026-0257Authentication BypassPalo Alto Networks PAN-OSPatch nowRansomware use, listed within a year0.97
CVE-2017-15944Remote Code ExecutionPalo Alto Networks PAN-OSPatch this weekMetasploit module; EPSS 0.98; verified Exploit-DB entry0.98
CVE-2024-0012Management Interface Authentication BypassPalo Alto Networks PAN-OSPatch this weekRansomware use; Metasploit module; EPSS 0.990.99
CVE-2024-9474Management Interface OS Command InjectionPalo Alto Networks PAN-OSPatch this weekRansomware use; Metasploit module; EPSS 0.950.95
CVE-2024-3400Command InjectionPalo Alto Networks PAN-OSPatch this weekRansomware use; Metasploit module; EPSS 0.990.99
CVE-2025-0108Authentication BypassPalo Alto Networks PAN-OSPatch this weekEPSS 0.980.98
CVE-2019-1579Remote Code ExecutionPalo Alto Networks PAN-OSPatch this weekRansomware use0.46
CVE-2020-2021Authentication BypassPalo Alto Networks PAN-OSPatch this weekRansomware use0.04
CVE-2026-0300Out-of-bounds WritePalo Alto Networks PAN-OSPatch soon0.32
CVE-2024-3393Malicious DNS PacketPalo Alto Networks PAN-OSPatch soon0.29

All 12 entries for PAN-OS

Read further