QID 730420

Date Published: 2022-04-07

QID 730420: Palo Alto Networks (PAN-OS) Impact of the Open Secure Sockets Layer (OpenSSL) Infinite Loop Vulnerability (PAN-190175, PAN-190223)

PAN OS is the software that runs all Palo Alto Networks next-generation firewalls.

The Palo Alto Networks Product Security Assurance team is evaluating the OpenSSL infinite loop vulnerability (CVE-2022-0778) as it relates to our products.

Affected Versions:
PAN-OS 10.2 versions earlier than PAN-OS 10.2.1
PAN-OS 10.1 versions earlier than PAN-OS 10.1.5-hf
PAN-OS 10.0 versions earlier than PAN-OS 10.0.10
PAN-OS 9.1 versions earlier than PAN-OS 9.1.13-hf
PAN-OS 9.0 versions earlier than PAN-OS 9.0.16-hf
PAN-OS 8.1 versions earlier than PAN-OS 8.1.23


QID Detection Logic (Authenticated):

This QID looks for the vulnerable version of PAN-OS

NOTE:

The Palo Alto Networks Product Security Assurance team is evaluating the OpenSSL infinite loop vulnerability (CVE-2022-0778) as it relates to our products.

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution

    Refer to PAN-190175, PAN-190223 for more information about patching this vulnerability.



    CVEs related to QID 730420

    Software Advisories
    Advisory ID Software Component Link
    PAN-190175, PAN-190223 URL Logo security.paloaltonetworks.com/CVE-2022-0778