QID 730421

QID 730421: Palo Alto Networks (PAN-OS) Impact of Spring Vulnerabilities CVE-2022-22963 and CVE-2022-22965 Vulnerability (PAN-191178)

PAN OS is the software that runs all Palo Alto Networks next-generation firewalls.

The Palo Alto Networks Product Security Assurance team is evaluating the Spring Cloud Function vulnerability CVE-2022-22963 and Spring Core vulnerability CVE-2022-22965 as it relates to our products. This is a developing product security incident and additional product status could be added and changed as more information becomes available.

Affected Versions:


QID Detection Logic (Authenticated):

This QID looks for the vulnerable version of PAN-OS

The Palo Alto Networks Product Security Assurance team is evaluating the Spring Cloud Function vulnerability CVE-2022-22963 and Spring Core vulnerability CVE-2022-22965 as it relates to our products. This is a developing product security incident and additional product status could be added and changed as more information becomes available.

  • CVSS V3 rated as Critical - 8.6 severity.
  • CVSS V2 rated as Medium - 5.4 severity.
  • Solution

    Refer to PAN-191178 for more information about patching this vulnerability.



    Workaround:
    No workarounds or mitigations are required for Palo Alto Networks products at this time. Customers with a Threat Prevention subscription can block the attack traffic related to these vulnerabilities by enabling Threat IDs 92393 and 92394 for CVE-2022-22965 and Threat ID 92389 for CVE-2022-22963. See https://unit42.paloaltonetworks.com/cve-2022-22965-springshell/ for more details on Palo Alto Networks product capabilities to protect against attacks that exploit this issue.

    Vendor References

    CVEs related to QID 730421

    Software Advisories
    Advisory ID Software Component Link
    PAN-191178 URL Logo security.paloaltonetworks.com/CVE-2022-22963