漏洞标题
PAN-OS: URL 过滤中的扩展拒绝服务(DoS)漏洞反映
漏洞描述信息
PAN-OS:URL过滤中的反射放大拒绝服务(DoS)漏洞
CVSS信息
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
漏洞类别
N/A
漏洞标题
PAN-OS: Reflected Amplification Denial-of-Service (DoS) Vulnerability in URL Filtering
漏洞描述信息
A PAN-OS URL filtering policy misconfiguration could allow a network-based attacker to conduct reflected and amplified TCP denial-of-service (RDoS) attacks. The DoS attack would appear to originate from a Palo Alto Networks PA-Series (hardware), VM-Series (virtual) and CN-Series (container) firewall against an attacker-specified target. To be misused by an external attacker, the firewall configuration must have a URL filtering profile with one or more blocked categories assigned to a source zone that has an external facing interface. This configuration is not typical for URL filtering and, if set, is likely unintended by the administrator. If exploited, this issue would not impact the confidentiality, integrity, or availability of our products. However, the resulting denial-of-service (DoS) attack may help obfuscate the identity of the attacker and implicate the firewall as the source of the attack. We have taken prompt action to address this issue in our PAN-OS software. All software updates for this issue are expected to be released no later than the week of August 15, 2022. This issue does not impact Panorama M-Series or Panorama virtual appliances. This issue has been resolved for all Cloud NGFW and Prisma Access customers and no additional action is required from them.
CVSS信息
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
漏洞类别
对网络消息容量的控制不充分(网络放大攻击)
漏洞标题
Palo Alto Networks PAN-OS 安全漏洞
漏洞描述信息
Palo Alto Networks PAN-OS是Palo Alto Networks的一款下一代防火墙软件。 Palo Alto Networks PAN-OS URL存在安全漏洞,该漏洞源于过滤策略配置错误。攻击者利用该漏洞执行拒绝服务攻击。
CVSS信息
N/A
漏洞类别
其他