Vulnerability record · CVE-2022-0028 · published 10 August 2022
CVE-2022-0028: PAN-OS URL filtering misconfiguration enables reflected TCP DoS
Paloaltonetworks · Pan Os
A PAN-OS URL filtering policy misconfiguration allows a network-based attacker to use PA-Series, VM-Series and CN-Series firewalls to conduct reflected and amplified TCP denial-of-service attacks against an attacker-specified target. The firewall must have a URL filtering profile with blocked categories assigned to a source zone with an external-facing interface, a configuration the vendor calls atypical and likely unintended. The flaw does not affect the confidentiality, integrity or availability of the firewall itself, but it lets attackers hide behind the firewall's IP while it floods a third party.
Description
A PAN-OS URL filtering policy misconfiguration could allow a network-based attacker to conduct reflected and amplified TCP denial-of-service (RDoS) attacks. The DoS attack would appear to originate from a Palo Alto Networks PA-Series (hardware), VM-Series (virtual) and CN-Series (container) firewall against an attacker-specified target. To be misused by an external attacker, the firewall configuration must have a URL filtering profile with one or more blocked categories assigned to a source zone that has an external facing interface. This configuration is not typical for URL filtering and, if set, is likely unintended by the administrator. If exploited, this issue would not impact the confidentiality, integrity, or availability of our products. However, the resulting denial-of-service (DoS) attack may help obfuscate the identity of the attacker and implicate the firewall as the source of the attack. We have taken prompt action to address this issue in our PAN-OS software. All software updates for this issue are expected to be released no later than the week of August 15, 2022. This issue does not impact Panorama M-Series or Panorama virtual appliances. This issue has been resolved for all Cloud NGFW and Prisma Access customers and no additional action is required from them.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
Automated analysis
high priorityIt is in CISA KEV with known exploitation and a CVSS of 8.6, but it requires a specific non-default URL filtering configuration and harms a third-party target rather than the firewall itself.
What it is
A PAN-OS URL filtering policy misconfiguration allows a network-based attacker to use PA-Series, VM-Series and CN-Series firewalls to conduct reflected and amplified TCP denial-of-service attacks against an attacker-specified target. The firewall must have a URL filtering profile with blocked categories assigned to a source zone with an external-facing interface, a configuration the vendor calls atypical and likely unintended. The flaw does not affect the confidentiality, integrity or availability of the firewall itself, but it lets attackers hide behind the firewall's IP while it floods a third party.
Impact
The attacker gains a reflected, amplified denial-of-service capability against a chosen target, degrading that target's availability. The firewall is implicated as the apparent source, which can obfuscate the attacker's identity and shift blame or scrutiny onto the firewall owner.
Attack surface
Reachable over the network with no authentication and no user interaction (CVSS AV:N/PR:N/UI:N). It requires the non-default condition that a URL filtering profile with blocked categories be bound to a source zone on an external-facing interface.
Exploitation
CISA added it to the KEV catalog on 2022-08-22 with a 2022-09-12 remediation due date, indicating known exploitation; EPSS 30-day probability is about 2.4 percent (83rd percentile). No ransomware campaign use is documented.
What to do
- Apply the PAN-OS software updates released for this issue per vendor instructions, prioritizing internet-facing firewalls.
- Audit security policies for URL filtering profiles with blocked categories attached to source zones on external-facing interfaces and remove or correct unintended bindings.
- Where patching is not immediately possible, remove the offending URL filtering profile from externally facing source zones as a temporary workaround.
- Confirm Cloud NGFW and Prisma Access are covered by the vendor's resolution and require no further action.
- Track remediation against the CISA KEV due date of 2022-09-12.
Detection
- Monitor firewall logs for outbound TCP traffic from the firewall itself to arbitrary external destinations that is not part of normal management or update behavior.
- Alert on abuse or takedown reports naming your firewall IP as the source of a denial-of-service attack.
- Review configuration change logs for URL filtering profiles newly bound to source zones with external-facing interfaces.
- Baseline and alert on abnormal outbound connection volume or SYN patterns originating from the firewall's external interface.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2022-0028 to the Known Exploited Vulnerabilities catalog on 22 August 2022 as "Palo Alto Networks PAN-OS Reflected Amplification Denial-of-Service Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 12 September 2022.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://security.paloaltonetworks.com/CVE-2022-0028 | MitigationThird Party Advisory |
| https://security.paloaltonetworks.com/CVE-2022-0028 | MitigationThird Party Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-0028 | US Government Resource |
Track CVE-2022-0028 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2022-0028), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.