CVE-2022-0028
Palo Alto Networks PAN-OS Reflected Amplification Denial-of-Service Vulnerability
- 대응 우선순위
- 최우선
- CVSS
- 8.6
- EPSS
- 2.02% 백분위 78.6% · 2026.06.27 기준
- CISA KEV
- 등록
- 조치 기한
- 2022.09.12
- 공개일
- 2022.08.11
CISA KEV에 등록된 실제 악용 확인 취약점
A PAN-OS URL filtering policy misconfiguration could allow a network-based attacker to conduct reflected and amplified TCP denial-of-service (RDoS) attacks. The DoS attack would appear to originate from a Palo Alto Networks PA-Series (hardware), VM-Series (virtual) and CN-Series (container) firewall against an attacker-specified target. To be misused by an external attacker, the firewall configuration must have a URL filtering profile with one or more blocked categories assigned to a source zone that has an external facing interface. This configuration is not typical for URL filtering and,...
공급사 Palo Alto Networks
제품 PAN-OS
영향 버전 8.1, 9.0, 9.1, 10.0, 10.1, 10.2, 8.1.0, 9.0.0, 9.1.0, 10.0.0, 10.1.0, 10.2.0, >= 8.1.0 < 8.1.23, >= 9.0.0 < 9.0.16, >= 9.1.0 < 9.1.14, >= 10.0.0 < 10.0.11, >= 10.1.0 < 10.1.6, >= 10.2.0 < 10.2.2, 8.1.23, 9.0.16
수정 버전 8.1.23, 9.0.16, 9.1.14, 10.0.11, 10.1.6, 10.2.2
Apply updates per vendor instructions.
조치 기한: 2022.09.12CVSS 벡터 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
CWE CWE-406, CWE-940
KEV 등록일 2022.08.22
랜섬웨어 캠페인 사용 미확인
CISA 비고 https://security.paloaltonetworks.com/CVE-2022-0028; https://nvd.nist.gov/vuln/detail/CVE-2022-0028
EPSS 데이터 기준일 2026.06.27