LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2022-0028: Palo Alto Networks PAN-OS Reflected Amplification Denial-of-Service Vulnerability

RBRecent Breaches Vulnerability Intelligence·Aug 22, 2022
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Sep 12, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2022-0028 to its Known Exploited Vulnerabilities catalog on Aug 22, 2022, with a federal patch deadline of Sep 12, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

A Palo Alto Networks PAN-OS URL filtering policy misconfiguration could allow a network-based attacker to conduct reflected and amplified TCP denial-of-service (RDoS) attacks.

CVE-2022-0028 is a reflected amplification denial-of-service vulnerability in Palo Alto Networks PAN-OS. A misconfiguration in URL filtering policy can let a network-based attacker bounce and amplify TCP traffic, turning the firewall into a reflector that helps flood a target. It matters because devices meant to protect the network can instead be abused to disrupt availability elsewhere, and the impact depends on how URL filtering is configured.

Public detail is limited to the CISA description and the assigned weakness; confirm exact conditions, fixed releases, and any configuration prerequisites directly against the vendor advisory.

How it works

The underlying weakness is CWE-940 (improper verification of the source of a communication channel). In this case, a URL filtering policy misconfiguration on PAN-OS can cause the device to respond to crafted requests in a way that reflects and amplifies TCP traffic toward a victim chosen by the attacker.

An attacker on the network sends traffic that the firewall processes under the misconfigured policy. Instead of dropping or properly validating the source, the device generates larger or more numerous responses directed at the attacker-specified target. The result is a reflected denial-of-service (RDoS) condition that consumes bandwidth or resources on the victim side. No further exploit mechanics are provided in the public summary; treat any deeper technical claims as unconfirmed until verified in the vendor advisory.

Am I affected? How to find it in your systems

PAN-OS runs on Palo Alto Networks next-generation firewalls and related security appliances, commonly deployed at internet edges, data-center perimeters, and segment boundaries. Inventory every firewall, panorama-managed device, and virtual PAN-OS instance in your environment.

How to remediate

Patch first. Apply the updates published by Palo Alto Networks for CVE-2022-0028 exactly as described in the vendor advisory and follow CISA’s direction to apply updates per vendor instructions.

If you can't patch immediately

Reduce exposure until the vendor update can be applied.

If your data may have been exposed

This vulnerability is a denial-of-service issue; the public record does not document ransomware use or direct data exfiltration. Actively exploited vulnerabilities can still lead to broader incidents if an attacker uses the disruption as cover or pivots afterward. If you suspect compromise, follow your incident-response plan, preserve logs, and review adjacent systems. You can also run a free exposure scan of your email addresses against known breach data sets to check whether credentials or personal information have appeared in prior breaches.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedPalo Alto Networks · PAN-OS
WeaknessCWE-940
Added to CISA KEVAug 22, 2022
Federal patch deadlineSep 12, 2022
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities