Executive brief
A misconfiguration in Palo Alto Networks PAN-OS URL filtering policies allows network-based attackers to perform reflected and amplified TCP denial-of-service (RDoS) attacks. The vulnerability occurs when a URL filtering profile with blocked categories is assigned to a source zone with an external-facing interface, causing the firewall to appear as the source of the attack against a specified target.
Affected products
- Palo Alto Networks PAN-OS 8.1 to 8.1.23-h1, 9.0 to 9.0.16-h3, 9.1 to 9.1.14-h4, 10.0 to 10.0.11-h1, 10.1 to 10.1.6-h6, 10.2 to 10.2.2-h2
Timeline
- 2022-08-15: patched: Software updates released the week of August 15, 2022.
- 2022-08-22: disclosed
- 2022-08-22: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.
- 2022-08-22: exploited: Reported as exploited in the wild.