Palo Alto Networks Security Advisories
Queries the public repository of PAN-OS CVEs.
Vulnerability Management · Security Advisories by Palo Alto Networks · Feed
Details
| ID | Palo Alto Networks Security Advisories |
|---|---|
| Provider | Palo Alto Networks |
| Category | Vulnerability Management |
| From Version | 6.5.0 |
| Docker Image | demisto/python3:3.12.13.10116658 |
| Supported Modules | Agentix XSIAM |
README
Queries the public repository of PAN-OS CVEs.
This integration was integrated and tested with the beta version 1 of the Palo Alto Networks Security Advisories API.
The Palo Alto Networks Security Advisories API is a representation of the GUI; https://security.paloaltonetworks.com/
Configure Palo Alto Networks Security Advisories in Cortex
| Parameter | Required |
|---|---|
| Default URL for PAN-OS advisories website | False |
| Fetch indicator product name | False |
Commands
You can execute these commands from the CLI, as part of an automation, or in a playbook.
After you successfully execute a command, a DBot message appears in the War Room with the command details.
pan-advisories-get-advisories
Gets all the advisories for the given product.
Base Command
pan-advisories-get-advisories
Input
| Argument Name | Description | Required |
|---|---|---|
| product | Product name to search for advisories. | Required |
| sort | Sort returned advisories by this value, can be date, cvss, etc. Leading hyphpen (-) indicates reverse search. Default is -date. | Optional |
| severity | Filter advisories to this severity level only. Possible values are: HIGH, CRITICAL, MEDIUM, LOW, NONE. | Optional |
| q | Text search query. | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| PANSecurityAdvisory.Advisory.data_type | Unknown | The type of advisory this is |
| PANSecurityAdvisory.Advisory.data_format | Unknown | The format of the advisory, such as MITRE |
| PANSecurityAdvisory.Advisory.cve_id | Unknown | The ID of the CVE described by this advisory |
| PANSecurityAdvisory.Advisory.cve_date_public | Unknown | The date this CVE was released |
| PANSecurityAdvisory.Advisory.cve_title | Unknown | The name of this CVE |
| PANSecurityAdvisory.Advisory.description | Unknown | Human readable description of Advisory |
| PANSecurityAdvisory.Advisory.cvss_score | Unknown | The CVSS Score |
| PANSecurityAdvisory.Advisory.cvss_severity | Unknown | The CVSS Severity |
| PANSecurityAdvisory.Advisory.cvss_vector_string | Unknown | The CVSS Vector string |
| PANSecurityAdvisory.Advisory.affected_version_list | Unknown | List of affected versions strings |
Command example
!pan-advisories-get-advisories product="PAN-OS" q=CVE-2022-0778
Context Example
{
"PANSecurityAdvisory": {
"Advisory": [
{
"affected_version_list": [
"Prisma Access 3.0",
"Prisma Access 2.2",
"Prisma Access 2.1",
"PAN-OS 10.2.0",
"PAN-OS 10.2",
"PAN-OS 10.1.5",
"PAN-OS 10.1.4-h4",
"PAN-OS 10.1.4-h3",
"PAN-OS 10.1.4-h2",
"PAN-OS 10.1.4-h1",
"PAN-OS 10.1.4",
"PAN-OS 10.1.3",
"PAN-OS 10.1.2",
"PAN-OS 10.1.1",
"PAN-OS 10.1.0",
"PAN-OS 10.1",
"PAN-OS 10.0.9",
"PAN-OS 10.0.8-h8",
"PAN-OS 10.0.8-h7",
"PAN-OS 10.0.8-h6",
"PAN-OS 10.0.8-h5",
"PAN-OS 10.0.8-h4",
"PAN-OS 10.0.8-h3",
"PAN-OS 10.0.8-h2",
"PAN-OS 10.0.8-h1",
"PAN-OS 10.0.8",
"PAN-OS 10.0.7",
"PAN-OS 10.0.6",
"PAN-OS 10.0.5",
"PAN-OS 10.0.4",
"PAN-OS 10.0.3",
"PAN-OS 10.0.2",
"PAN-OS 10.0.1",
"PAN-OS 10.0.0",
"PAN-OS 10.0",
"PAN-OS 9.1.13",
"PAN-OS 9.1.12-h3",
"PAN-OS 9.1.12-h2",
"PAN-OS 9.1.12-h1",
"PAN-OS 9.1.12",
"PAN-OS 9.1.11-h3",
"PAN-OS 9.1.11-h2",
"PAN-OS 9.1.11-h1",
"PAN-OS 9.1.11",
"PAN-OS 9.1.10",
"PAN-OS 9.1.9",
"PAN-OS 9.1.8",
"PAN-OS 9.1.7",
"PAN-OS 9.1.6",
"PAN-OS 9.1.5",
"PAN-OS 9.1.4",
"PAN-OS 9.1.3-h1",
"PAN-OS 9.1.3",
"PAN-OS 9.1.2-h1",
"PAN-OS 9.1.2",
"PAN-OS 9.1.1",
"PAN-OS 9.1.0-h3",
"PAN-OS 9.1.0-h2",
"PAN-OS 9.1.0-h1",
"PAN-OS 9.1.0",
"PAN-OS 9.1",
"PAN-OS 9.0.16",
"PAN-OS 9.0.15",
"PAN-OS 9.0.14-h4",
"PAN-OS 9.0.14-h3",
"PAN-OS 9.0.14-h2",
"PAN-OS 9.0.14-h1",
"PAN-OS 9.0.14",
"PAN-OS 9.0.13",
"PAN-OS 9.0.12",
"PAN-OS 9.0.11",
"PAN-OS 9.0.10",
"PAN-OS 9.0.9-h1",
"PAN-OS 9.0.9",
"PAN-OS 9.0.8",
"PAN-OS 9.0.7",
"PAN-OS 9.0.6",
"PAN-OS 9.0.5",
"PAN-OS 9.0.4",
"PAN-OS 9.0.3-h3",
"PAN-OS 9.0.3-h2",
"PAN-OS 9.0.3-h1",
"PAN-OS 9.0.3",
"PAN-OS 9.0.2-h4",
"PAN-OS 9.0.2-h3",
"PAN-OS 9.0.2-h2",
"PAN-OS 9.0.2-h1",
"PAN-OS 9.0.2",
"PAN-OS 9.0.1",
"PAN-OS 9.0.0",
"PAN-OS 9.0",
"PAN-OS 8.1.22",
"PAN-OS 8.1.21-h1",
"PAN-OS 8.1.21",
"PAN-OS 8.1.20-h1",
"PAN-OS 8.1.20",
"PAN-OS 8.1.19",
"PAN-OS 8.1.18",
"PAN-OS 8.1.17",
"PAN-OS 8.1.16",
"PAN-OS 8.1.15-h3",
"PAN-OS 8.1.15-h2",
"PAN-OS 8.1.15-h1",
"PAN-OS 8.1.15",
"PAN-OS 8.1.14-h2",
"PAN-OS 8.1.14-h1",
"PAN-OS 8.1.14",
"PAN-OS 8.1.13",
"PAN-OS 8.1.12",
"PAN-OS 8.1.11",
"PAN-OS 8.1.10",
"PAN-OS 8.1.9-h4",
"PAN-OS 8.1.9-h3",
"PAN-OS 8.1.9-h2",
"PAN-OS 8.1.9-h1",
"PAN-OS 8.1.9",
"PAN-OS 8.1.8-h5",
"PAN-OS 8.1.8-h4",
"PAN-OS 8.1.8-h3",
"PAN-OS 8.1.8-h2",
"PAN-OS 8.1.8-h1",
"PAN-OS 8.1.8",
"PAN-OS 8.1.7",
"PAN-OS 8.1.6-h2",
"PAN-OS 8.1.6-h1",
"PAN-OS 8.1.6",
"PAN-OS 8.1.5",
"PAN-OS 8.1.4",
"PAN-OS 8.1.3",
"PAN-OS 8.1.2",
"PAN-OS 8.1.1",
"PAN-OS 8.1.0",
"PAN-OS 8.1",
"GlobalProtect App",
"Cortex XDR Agent"
],
"cve_date_public": "2022-03-31T02:30:00.000Z",
"cve_id": "CVE-2022-0778",
"cve_title": "Impact of the OpenSSL Infinite Loop Vulnerability CVE-2022-0778",
"cvss_score": 7.5,
"cvss_severity": "HIGH",
"cvss_vector_string": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"data_format": "MITRE",
"data_type": "CVE",
"description": "The Palo Alto Networks Product Security Assurance team is evaluating the OpenSSL infinite loop vulnerability (CVE-2022-0778) as it relates to our products.\n\nThis vulnerability causes the OpenSSL library to enter an infinite loop when parsing an invalid certificate and can result in a Denial-of-Service (DoS) to the application. An attacker does not need a verified certificate to exploit this vulnerability because parsing a bad certificate triggers the infinite loop before the verification process is completed.\n\nThe Cortex XSOAR product is not impacted by this vulnerability. However, PAN-OS, GlobalProtect app, and Cortex XDR agent software contain a vulnerable version of the OpenSSL library and product availability is impacted by this vulnerability. For PAN-OS software, this includes both hardware and virtual firewalls and Panorama appliances as well as Prisma Access customers. This vulnerability has reduced severity on Cortex XDR agent and Global Protect app as successful exploitation requires an attacker-in-the-middle attack (MITM): 5.9 Medium (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H).\n\nWe are working diligently on fixes to remove the vulnerable code from our PAN-OS, GlobalProtect app, and Cortex XDR agent software. The fixed versions for hotfixes and other product upgrades will be updated in this advisory as soon as possible."
}
]
}
}
Human Readable Output
Palo Alto Networks Security Advisories
affected_version_list affects_vendor_name cve_date_public cve_id cve_title cvss_score cvss_severity cvss_vector_string data_format data_type description Prisma Access 3.0,
Prisma Access 2.2,
Prisma Access 2.1,
PAN-OS 10.2.0,
PAN-OS 10.2,
PAN-OS 10.1.5,
PAN-OS 10.1.4-h4,
PAN-OS 10.1.4-h3,
PAN-OS 10.1.4-h2,
PAN-OS 10.1.4-h1,
PAN-OS 10.1.4,
PAN-OS 10.1.3,
PAN-OS 10.1.2,
PAN-OS 10.1.1,
PAN-OS 10.1.0,
PAN-OS 10.1,
PAN-OS 10.0.9,
PAN-OS 10.0.8-h8,
PAN-OS 10.0.8-h7,
PAN-OS 10.0.8-h6,
PAN-OS 10.0.8-h5,
PAN-OS 10.0.8-h4,
PAN-OS 10.0.8-h3,
PAN-OS 10.0.8-h2,
PAN-OS 10.0.8-h1,
PAN-OS 10.0.8,
PAN-OS 10.0.7,
PAN-OS 10.0.6,
PAN-OS 10.0.5,
PAN-OS 10.0.4,
PAN-OS 10.0.3,
PAN-OS 10.0.2,
PAN-OS 10.0.1,
PAN-OS 10.0.0,
PAN-OS 10.0,
PAN-OS 9.1.13,
PAN-OS 9.1.12-h3,
PAN-OS 9.1.12-h2,
PAN-OS 9.1.12-h1,
PAN-OS 9.1.12,
PAN-OS 9.1.11-h3,
PAN-OS 9.1.11-h2,
PAN-OS 9.1.11-h1,
PAN-OS 9.1.11,
PAN-OS 9.1.10,
PAN-OS 9.1.9,
PAN-OS 9.1.8,
PAN-OS 9.1.7,
PAN-OS 9.1.6,
PAN-OS 9.1.5,
PAN-OS 9.1.4,
PAN-OS 9.1.3-h1,
PAN-OS 9.1.3,
PAN-OS 9.1.2-h1,
PAN-OS 9.1.2,
PAN-OS 9.1.1,
PAN-OS 9.1.0-h3,
PAN-OS 9.1.0-h2,
PAN-OS 9.1.0-h1,
PAN-OS 9.1.0,
PAN-OS 9.1,
PAN-OS 9.0.16,
PAN-OS 9.0.15,
PAN-OS 9.0.14-h4,
PAN-OS 9.0.14-h3,
PAN-OS 9.0.14-h2,
PAN-OS 9.0.14-h1,
PAN-OS 9.0.14,
PAN-OS 9.0.13,
PAN-OS 9.0.12,
PAN-OS 9.0.11,
PAN-OS 9.0.10,
PAN-OS 9.0.9-h1,
PAN-OS 9.0.9,
PAN-OS 9.0.8,
PAN-OS 9.0.7,
PAN-OS 9.0.6,
PAN-OS 9.0.5,
PAN-OS 9.0.4,
PAN-OS 9.0.3-h3,
PAN-OS 9.0.3-h2,
PAN-OS 9.0.3-h1,
PAN-OS 9.0.3,
PAN-OS 9.0.2-h4,
PAN-OS 9.0.2-h3,
PAN-OS 9.0.2-h2,
PAN-OS 9.0.2-h1,
PAN-OS 9.0.2,
PAN-OS 9.0.1,
PAN-OS 9.0.0,
PAN-OS 9.0,
PAN-OS 8.1.22,
PAN-OS 8.1.21-h1,
PAN-OS 8.1.21,
PAN-OS 8.1.20-h1,
PAN-OS 8.1.20,
PAN-OS 8.1.19,
PAN-OS 8.1.18,
PAN-OS 8.1.17,
PAN-OS 8.1.16,
PAN-OS 8.1.15-h3,
PAN-OS 8.1.15-h2,
PAN-OS 8.1.15-h1,
PAN-OS 8.1.15,
PAN-OS 8.1.14-h2,
PAN-OS 8.1.14-h1,
PAN-OS 8.1.14,
PAN-OS 8.1.13,
PAN-OS 8.1.12,
PAN-OS 8.1.11,
PAN-OS 8.1.10,
PAN-OS 8.1.9-h4,
PAN-OS 8.1.9-h3,
PAN-OS 8.1.9-h2,
PAN-OS 8.1.9-h1,
PAN-OS 8.1.9,
PAN-OS 8.1.8-h5,
PAN-OS 8.1.8-h4,
PAN-OS 8.1.8-h3,
PAN-OS 8.1.8-h2,
PAN-OS 8.1.8-h1,
PAN-OS 8.1.8,
PAN-OS 8.1.7,
PAN-OS 8.1.6-h2,
PAN-OS 8.1.6-h1,
PAN-OS 8.1.6,
PAN-OS 8.1.5,
PAN-OS 8.1.4,
PAN-OS 8.1.3,
PAN-OS 8.1.2,
PAN-OS 8.1.1,
PAN-OS 8.1.0,
PAN-OS 8.1,
GlobalProtect App,
Cortex XDR AgentPalo Alto Networks 2022-03-31T02:30:00.000Z CVE-2022-0778 Impact of the OpenSSL Infinite Loop Vulnerability CVE-2022-0778 7.5 HIGH CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H MITRE CVE The Palo Alto Networks Product Security Assurance team is evaluating the OpenSSL infinite loop vulnerability (CVE-2022-0778) as it relates to our products.
This vulnerability causes the OpenSSL library to enter an infinite loop when parsing an invalid certificate and can result in a Denial-of-Service (DoS) to the application. An attacker does not need a verified certificate to exploit this vulnerability because parsing a bad certificate triggers the infinite loop before the verification process is completed.
The Cortex XSOAR product is not impacted by this vulnerability. However, PAN-OS, GlobalProtect app, and Cortex XDR agent software contain a vulnerable version of the OpenSSL library and product availability is impacted by this vulnerability. For PAN-OS software, this includes both hardware and virtual firewalls and Panorama appliances as well as Prisma Access customers. This vulnerability has reduced severity on Cortex XDR agent and Global Protect app as successful exploitation requires an attacker-in-the-middle attack (MITM): 5.9 Medium (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H).
We are working diligently on fixes to remove the vulnerable code from our PAN-OS, GlobalProtect app, and Cortex XDR agent software. The fixed versions for hotfixes and other product upgrades will be updated in this advisory as soon as possible.
Configuration parameters
url— Default URL for PAN-OS advisories websitefetch_product_name— Fetch indicator product namefeed— Fetch indicatorsfeedReputation— Indicator ReputationfeedReliability— Source Reliability (required)feedExpirationPolicy—feedExpirationInterval—feedFetchInterval— Feed Fetch IntervalfeedBypassExclusionList— Bypass exclusion listfeedTags— Tagstlp_color— Traffic Light Protocol Color
Commands (1)
-
pan-advisories-get-advisoriesGets all the advisories for the given product.
category: Vulnerability Management provider: Palo Alto Networks sectionorder: - Connect - Collect commonfields: id: Palo Alto Networks Security Advisories version: -1 configuration: - defaultvalue: https://security.paloaltonetworks.com/api/v1 display: Default URL for PAN-OS advisories website name: url type: 0 required: false section: Connect - additionalinfo: The Palo Alto Networks product name to fetch indicators for, such as "PAN-OS" defaultvalue: PAN-OS display: Fetch indicator product name name: fetch_product_name type: 0 required: false section: Collect - name: feed defaultvalue: 'true' display: Fetch indicators type: 8 required: false section: Collect - name: feedReputation display: Indicator Reputation type: 18 options: - None - Good - Suspicious - Bad additionalinfo: Indicators from this integration instance will be marked with this reputation required: false section: Collect - name: feedReliability display: Source Reliability type: 15 required: true options: - A - Completely reliable - B - Usually reliable - C - Fairly reliable - D - Not usually reliable - E - Unreliable - F - Reliability cannot be judged additionalinfo: Reliability of the source providing the intelligence data section: Collect - name: feedExpirationPolicy display: '' type: 17 options: - never - interval - indicatorType - suddenDeath required: false section: Collect - name: feedExpirationInterval display: '' type: 1 required: false section: Collect - name: feedFetchInterval display: Feed Fetch Interval type: 19 required: false section: Collect - name: feedBypassExclusionList display: Bypass exclusion list type: 8 additionalinfo: When selected, the exclusion list is ignored for indicators from this feed. This means that if an indicator from this feed is on the exclusion list, the indicator might still be added to the system. required: false section: Collect - name: feedTags display: Tags type: 0 additionalinfo: Supports CSV values. required: false section: Collect - name: tlp_color display: Traffic Light Protocol Color options: - RED - AMBER - GREEN - WHITE type: 15 additionalinfo: The Traffic Light Protocol (TLP) designation to apply to indicators fetched from the feed required: false section: Collect description: Queries the public repository of PAN-OS CVEs. display: Palo Alto Networks Security Advisories (Beta) beta: true name: Palo Alto Networks Security Advisories script: commands: - arguments: - default: true defaultValue: PAN-OS description: Product name to search for advisories; valid values for this item can be found in the sidebar at https://security.paloaltonetworks.com/ name: product - defaultValue: -date description: Sort returned advisories by this value, can be date, cvss, etc. Leading hyphpen (-) indicates reverse search. name: sort - auto: PREDEFINED description: Filter advisories to this severity level only. name: severity predefined: - HIGH - CRITICAL - MEDIUM - LOW - NONE - description: Text search query - supports same search syntax as the GUI filter field. name: q description: Gets all the advisories for the given product. name: pan-advisories-get-advisories outputs: - contextPath: PANSecurityAdvisory.Advisory.data_type description: The type of advisory this is. type: String - contextPath: PANSecurityAdvisory.Advisory.data_format description: The format of the advisory, such as MITRE. type: String - contextPath: PANSecurityAdvisory.Advisory.cve_id description: The ID of the CVE described by this advisory. type: String - contextPath: PANSecurityAdvisory.Advisory.cve_date_public description: The date this CVE was released. type: String - contextPath: PANSecurityAdvisory.Advisory.cve_title description: The name of this CVE. type: String - contextPath: PANSecurityAdvisory.Advisory.description description: Human readable description of Advisory. type: String - contextPath: PANSecurityAdvisory.Advisory.cvss_score description: The CVSS Score. type: String - contextPath: PANSecurityAdvisory.Advisory.cvss_severity description: The CVSS Severity. type: String - contextPath: PANSecurityAdvisory.Advisory.cvss_vector_string description: The CVSS Vector string. type: String - contextPath: PANSecurityAdvisory.Advisory.affected_version_list description: List of affected versions strings. type: String dockerimage: demisto/python3:3.12.13.10116658 feed: true runonce: false script: '-' subtype: python3 type: python fromversion: 6.5.0 tests: - No tests (auto formatted)