← Vulnerability feed

Vulnerability record · CVE-2022-0028 · published 10 August 2022

CVE-2022-0028: PAN-OS URL filtering misconfiguration enables reflected TCP DoS

Paloaltonetworks · Pan Os

A PAN-OS URL filtering policy misconfiguration allows a network-based attacker to use PA-Series, VM-Series and CN-Series firewalls to conduct reflected and amplified TCP denial-of-service attacks against an attacker-specified target. The firewall must have a URL filtering profile with blocked categories assigned to a source zone with an external-facing interface, a configuration the vendor calls atypical and likely unintended. The flaw does not affect the confidentiality, integrity or availability of the firewall itself, but it lets attackers hide behind the firewall's IP while it floods a third party.

8.6 CVSS 3.1 High CISA KEV since 22 Aug 2022 EPSS 2.4% · top 16.8% CWE-406 · CWE-406
8.6CVSS 3.1 base score
2.4%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
3References
17 Jun 2026Last modified by NVD

Description

A PAN-OS URL filtering policy misconfiguration could allow a network-based attacker to conduct reflected and amplified TCP denial-of-service (RDoS) attacks. The DoS attack would appear to originate from a Palo Alto Networks PA-Series (hardware), VM-Series (virtual) and CN-Series (container) firewall against an attacker-specified target. To be misused by an external attacker, the firewall configuration must have a URL filtering profile with one or more blocked categories assigned to a source zone that has an external facing interface. This configuration is not typical for URL filtering and, if set, is likely unintended by the administrator. If exploited, this issue would not impact the confidentiality, integrity, or availability of our products. However, the resulting denial-of-service (DoS) attack may help obfuscate the identity of the attacker and implicate the firewall as the source of the attack. We have taken prompt action to address this issue in our PAN-OS software. All software updates for this issue are expected to be released no later than the week of August 15, 2022. This issue does not impact Panorama M-Series or Panorama virtual appliances. This issue has been resolved for all Cloud NGFW and Prisma Access customers and no additional action is required from them.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

high priorityIt is in CISA KEV with known exploitation and a CVSS of 8.6, but it requires a specific non-default URL filtering configuration and harms a third-party target rather than the firewall itself.

What it is

A PAN-OS URL filtering policy misconfiguration allows a network-based attacker to use PA-Series, VM-Series and CN-Series firewalls to conduct reflected and amplified TCP denial-of-service attacks against an attacker-specified target. The firewall must have a URL filtering profile with blocked categories assigned to a source zone with an external-facing interface, a configuration the vendor calls atypical and likely unintended. The flaw does not affect the confidentiality, integrity or availability of the firewall itself, but it lets attackers hide behind the firewall's IP while it floods a third party.

Impact

The attacker gains a reflected, amplified denial-of-service capability against a chosen target, degrading that target's availability. The firewall is implicated as the apparent source, which can obfuscate the attacker's identity and shift blame or scrutiny onto the firewall owner.

Attack surface

Reachable over the network with no authentication and no user interaction (CVSS AV:N/PR:N/UI:N). It requires the non-default condition that a URL filtering profile with blocked categories be bound to a source zone on an external-facing interface.

Exploitation

CISA added it to the KEV catalog on 2022-08-22 with a 2022-09-12 remediation due date, indicating known exploitation; EPSS 30-day probability is about 2.4 percent (83rd percentile). No ransomware campaign use is documented.

What to do

  • Apply the PAN-OS software updates released for this issue per vendor instructions, prioritizing internet-facing firewalls.
  • Audit security policies for URL filtering profiles with blocked categories attached to source zones on external-facing interfaces and remove or correct unintended bindings.
  • Where patching is not immediately possible, remove the offending URL filtering profile from externally facing source zones as a temporary workaround.
  • Confirm Cloud NGFW and Prisma Access are covered by the vendor's resolution and require no further action.
  • Track remediation against the CISA KEV due date of 2022-09-12.

Detection

  • Monitor firewall logs for outbound TCP traffic from the firewall itself to arbitrary external destinations that is not part of normal management or update behavior.
  • Alert on abuse or takedown reports naming your firewall IP as the source of a denial-of-service attack.
  • Review configuration change logs for URL filtering profiles newly bound to source zones with external-facing interfaces.
  • Baseline and alert on abnormal outbound connection volume or SYN patterns originating from the firewall's external interface.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2022-0028 to the Known Exploited Vulnerabilities catalog on 22 August 2022 as "Palo Alto Networks PAN-OS Reflected Amplification Denial-of-Service Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 12 September 2022.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2022-0028 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2024-3400PAN-OS GlobalProtect command injection allows unauthenticated root code executionA command injection caused by arbitrary file creation in the GlobalProtect feature of Palo Alto Networks PAN-OS lets an unauthenticated attacker run …KEVEPSS 100%analysed10.0CVE-2020-2021PAN-OS SAML signature verification bypass allows authentication bypassPAN-OS fails to properly verify SAML signatures when SAML authentication is enabled and the 'Validate Identity Provider Certificate' option is unchec…KEVEPSS 4.4%analysed9.8CVE-2017-15944PAN-OS management interface input validation flaw allows remote code executionPAN-OS versions before 6.1.19, 7.0.x before 7.0.19, 7.1.x before 7.1.14, and 8.0.x before 8.0.6 contain an input validation and memory buffer overflo…KEVEPSS 98%analysed9.3CVE-2026-0300PAN-OS User-ID Authentication Portal buffer overflow allows root code executionA buffer overflow (out-of-bounds write, CWE-787) in the User-ID Authentication Portal (Captive Portal) service of Palo Alto Networks PAN-OS lets an u…KEVEPSS 32%analysed9.3CVE-2024-0012PAN-OS Management Web Interface Authentication BypassPAN-OS contains a missing authentication flaw (CWE-306) in the management web interface that lets an unauthenticated network attacker obtain PAN-OS a…KEVEPSS 100%analysed8.8CVE-2025-0108PAN-OS management web interface authentication bypassPAN-OS contains a missing-authentication flaw (CWE-306) in the management web interface that lets an unauthenticated attacker with network access inv…KEVEPSS 98%analysed8.7CVE-2024-3393PAN-OS DNS Security packet causes firewall reboot and maintenance modeA denial of service flaw in the DNS Security feature of Palo Alto Networks PAN-OS lets an unauthenticated attacker send a crafted packet through the …KEVEPSS 28%analysed8.1CVE-2019-1579PAN-OS GlobalProtect pre-auth remote code executionPAN-OS versions 7.1.18, 8.0.11-h1 and 8.1.2 and earlier contain a remote code execution flaw (CWE-134, format string) that is reachable when the Glob…KEVEPSS 46%analysed

Source: NIST National Vulnerability Database (record CVE-2022-0028), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.