QID 730321
Date Published: 2021-12-30
QID 730321: Palo Alto Networks (PAN-OS) Invalid URLs in an External Dynamic List (EDL) can Lead to Firewall Outage Vulnerability (PAN-160455)
PAN OS is the software that runs all Palo Alto Networks next-generation firewalls.
Certain invalid URL entries contained in an External Dynamic List (EDL) cause the Device Server daemon (devsrvr) to stop responding.
Affected Versions:
PAN-OS 10.0 versions earlier than PAN-OS 10.0.5
PAN-OS 9.1 versions earlier than PAN-OS 9.1.9
PAN-OS 9.0 versions earlier than PAN-OS 9.0.14
QID Detection Logic (Authenticated):
This QID looks for the vulnerable version of PAN-OS
NOTE:This issue is applicable only if an External Dynamic List (EDL) is configured on the firewall.
An EDL that contains only domain names or IP addresses will not cause this issue.
Certain invalid URL entries contained in an External Dynamic List (EDL) cause the Device Server daemon (devsrvr) to stop responding.
Refer to PAN-160455 for more information about patching this vulnerability.
Workaround:
You can prevent this issue by removing all invalid URL entries from source EDLs or removing the EDL from your configuration.
Additionally, do not configure EDLs from websites that you do not trust.
- PAN-160455 -
security.paloaltonetworks.com/CVE-2021-3048
CVEs related to QID 730321
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| PAN-160455 |
|