Palo Alto Networks Security Advisories
Queries the public repository of PAN-OS CVEs.
Vulnerability Management · Security Advisories by Palo Alto Networks · Feed
Details
| ID | Palo Alto Networks Security Advisories |
|---|---|
| Provider | Palo Alto Networks |
| Category | Vulnerability Management |
| From Version | 6.5.0 |
| Docker Image | demisto/python3:3.12.13.10116658 |
| Supported Modules | Agentix XSIAM |
README
Queries the public repository of PAN-OS CVEs.
This integration was integrated and tested with the beta version 1 of the Palo Alto Networks Security Advisories API.
The Palo Alto Networks Security Advisories API is a representation of the GUI; https://security.paloaltonetworks.com/
Configure Palo Alto Networks Security Advisories in Cortex
| Parameter | Required |
|---|---|
| Default URL for PAN-OS advisories website | False |
| Fetch indicator product name | False |
Commands
You can execute these commands from the CLI, as part of an automation, or in a playbook.
After you successfully execute a command, a DBot message appears in the War Room with the command details.
pan-advisories-get-advisories
Gets all the advisories for the given product.
Base Command
pan-advisories-get-advisories
Input
| Argument Name | Description | Required |
|---|---|---|
| product | Product name to search for advisories. | Required |
| sort | Sort returned advisories by this value, can be date, cvss, etc. Leading hyphpen (-) indicates reverse search. Default is -date. | Optional |
| severity | Filter advisories to this severity level only. Possible values are: HIGH, CRITICAL, MEDIUM, LOW, NONE. | Optional |
| q | Text search query. | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| PANSecurityAdvisory.Advisory.data_type | Unknown | The type of advisory this is |
| PANSecurityAdvisory.Advisory.data_format | Unknown | The format of the advisory, such as MITRE |
| PANSecurityAdvisory.Advisory.cve_id | Unknown | The ID of the CVE described by this advisory |
| PANSecurityAdvisory.Advisory.cve_date_public | Unknown | The date this CVE was released |
| PANSecurityAdvisory.Advisory.cve_title | Unknown | The name of this CVE |
| PANSecurityAdvisory.Advisory.description | Unknown | Human readable description of Advisory |
| PANSecurityAdvisory.Advisory.cvss_score | Unknown | The CVSS Score |
| PANSecurityAdvisory.Advisory.cvss_severity | Unknown | The CVSS Severity |
| PANSecurityAdvisory.Advisory.cvss_vector_string | Unknown | The CVSS Vector string |
| PANSecurityAdvisory.Advisory.affected_version_list | Unknown | List of affected versions strings |
Command example
!pan-advisories-get-advisories product="PAN-OS" q=CVE-2022-0778
Context Example
{
"PANSecurityAdvisory": {
"Advisory": [
{
"affected_version_list": [
"Prisma Access 3.0",
"Prisma Access 2.2",
"Prisma Access 2.1",
"PAN-OS 10.2.0",
"PAN-OS 10.2",
"PAN-OS 10.1.5",
"PAN-OS 10.1.4-h4",
"PAN-OS 10.1.4-h3",
"PAN-OS 10.1.4-h2",
"PAN-OS 10.1.4-h1",
"PAN-OS 10.1.4",
"PAN-OS 10.1.3",
"PAN-OS 10.1.2",
"PAN-OS 10.1.1",
"PAN-OS 10.1.0",
"PAN-OS 10.1",
"PAN-OS 10.0.9",
"PAN-OS 10.0.8-h8",
"PAN-OS 10.0.8-h7",
"PAN-OS 10.0.8-h6",
"PAN-OS 10.0.8-h5",
"PAN-OS 10.0.8-h4",
"PAN-OS 10.0.8-h3",
"PAN-OS 10.0.8-h2",
"PAN-OS 10.0.8-h1",
"PAN-OS 10.0.8",
"PAN-OS 10.0.7",
"PAN-OS 10.0.6",
"PAN-OS 10.0.5",
"PAN-OS 10.0.4",
"PAN-OS 10.0.3",
"PAN-OS 10.0.2",
"PAN-OS 10.0.1",
"PAN-OS 10.0.0",
"PAN-OS 10.0",
"PAN-OS 9.1.13",
"PAN-OS 9.1.12-h3",
"PAN-OS 9.1.12-h2",
"PAN-OS 9.1.12-h1",
"PAN-OS 9.1.12",
"PAN-OS 9.1.11-h3",
"PAN-OS 9.1.11-h2",
"PAN-OS 9.1.11-h1",
"PAN-OS 9.1.11",
"PAN-OS 9.1.10",
"PAN-OS 9.1.9",
"PAN-OS 9.1.8",
"PAN-OS 9.1.7",
"PAN-OS 9.1.6",
"PAN-OS 9.1.5",
"PAN-OS 9.1.4",
"PAN-OS 9.1.3-h1",
"PAN-OS 9.1.3",
"PAN-OS 9.1.2-h1",
"PAN-OS 9.1.2",
"PAN-OS 9.1.1",
"PAN-OS 9.1.0-h3",
"PAN-OS 9.1.0-h2",
"PAN-OS 9.1.0-h1",
"PAN-OS 9.1.0",
"PAN-OS 9.1",
"PAN-OS 9.0.16",
"PAN-OS 9.0.15",
"PAN-OS 9.0.14-h4",
"PAN-OS 9.0.14-h3",
"PAN-OS 9.0.14-h2",
"PAN-OS 9.0.14-h1",
"PAN-OS 9.0.14",
"PAN-OS 9.0.13",
"PAN-OS 9.0.12",
"PAN-OS 9.0.11",
"PAN-OS 9.0.10",
"PAN-OS 9.0.9-h1",
"PAN-OS 9.0.9",
"PAN-OS 9.0.8",
"PAN-OS 9.0.7",
"PAN-OS 9.0.6",
"PAN-OS 9.0.5",
"PAN-OS 9.0.4",
"PAN-OS 9.0.3-h3",
"PAN-OS 9.0.3-h2",
"PAN-OS 9.0.3-h1",
"PAN-OS 9.0.3",
"PAN-OS 9.0.2-h4",
"PAN-OS 9.0.2-h3",
"PAN-OS 9.0.2-h2",
"PAN-OS 9.0.2-h1",
"PAN-OS 9.0.2",
"PAN-OS 9.0.1",
"PAN-OS 9.0.0",
"PAN-OS 9.0",
"PAN-OS 8.1.22",
"PAN-OS 8.1.21-h1",
"PAN-OS 8.1.21",
"PAN-OS 8.1.20-h1",
"PAN-OS 8.1.20",
"PAN-OS 8.1.19",
"PAN-OS 8.1.18",
"PAN-OS 8.1.17",
"PAN-OS 8.1.16",
"PAN-OS 8.1.15-h3",
"PAN-OS 8.1.15-h2",
"PAN-OS 8.1.15-h1",
"PAN-OS 8.1.15",
"PAN-OS 8.1.14-h2",
"PAN-OS 8.1.14-h1",
"PAN-OS 8.1.14",
"PAN-OS 8.1.13",
"PAN-OS 8.1.12",
"PAN-OS 8.1.11",
"PAN-OS 8.1.10",
"PAN-OS 8.1.9-h4",
"PAN-OS 8.1.9-h3",
"PAN-OS 8.1.9-h2",
"PAN-OS 8.1.9-h1",
"PAN-OS 8.1.9",
"PAN-OS 8.1.8-h5",
"PAN-OS 8.1.8-h4",
"PAN-OS 8.1.8-h3",
"PAN-OS 8.1.8-h2",
"PAN-OS 8.1.8-h1",
"PAN-OS 8.1.8",
"PAN-OS 8.1.7",
"PAN-OS 8.1.6-h2",
"PAN-OS 8.1.6-h1",
"PAN-OS 8.1.6",
"PAN-OS 8.1.5",
"PAN-OS 8.1.4",
"PAN-OS 8.1.3",
"PAN-OS 8.1.2",
"PAN-OS 8.1.1",
"PAN-OS 8.1.0",
"PAN-OS 8.1",
"GlobalProtect App",
"Cortex XDR Agent"
],
"cve_date_public": "2022-03-31T02:30:00.000Z",
"cve_id": "CVE-2022-0778",
"cve_title": "Impact of the OpenSSL Infinite Loop Vulnerability CVE-2022-0778",
"cvss_score": 7.5,
"cvss_severity": "HIGH",
"cvss_vector_string": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"data_format": "MITRE",
"data_type": "CVE",
"description": "The Palo Alto Networks Product Security Assurance team is evaluating the OpenSSL infinite loop vulnerability (CVE-2022-0778) as it relates to our products.\n\nThis vulnerability causes the OpenSSL library to enter an infinite loop when parsing an invalid certificate and can result in a Denial-of-Service (DoS) to the application. An attacker does not need a verified certificate to exploit this vulnerability because parsing a bad certificate triggers the infinite loop before the verification process is completed.\n\nThe Cortex XSOAR product is not impacted by this vulnerability. However, PAN-OS, GlobalProtect app, and Cortex XDR agent software contain a vulnerable version of the OpenSSL library and product availability is impacted by this vulnerability. For PAN-OS software, this includes both hardware and virtual firewalls and Panorama appliances as well as Prisma Access customers. This vulnerability has reduced severity on Cortex XDR agent and Global Protect app as successful exploitation requires an attacker-in-the-middle attack (MITM): 5.9 Medium (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H).\n\nWe are working diligently on fixes to remove the vulnerable code from our PAN-OS, GlobalProtect app, and Cortex XDR agent software. The fixed versions for hotfixes and other product upgrades will be updated in this advisory as soon as possible."
}
]
}
}
Human Readable Output
Palo Alto Networks Security Advisories
affected_version_list affects_vendor_name cve_date_public cve_id cve_title cvss_score cvss_severity cvss_vector_string data_format data_type description Prisma Access 3.0,
Prisma Access 2.2,
Prisma Access 2.1,
PAN-OS 10.2.0,
PAN-OS 10.2,
PAN-OS 10.1.5,
PAN-OS 10.1.4-h4,
PAN-OS 10.1.4-h3,
PAN-OS 10.1.4-h2,
PAN-OS 10.1.4-h1,
PAN-OS 10.1.4,
PAN-OS 10.1.3,
PAN-OS 10.1.2,
PAN-OS 10.1.1,
PAN-OS 10.1.0,
PAN-OS 10.1,
PAN-OS 10.0.9,
PAN-OS 10.0.8-h8,
PAN-OS 10.0.8-h7,
PAN-OS 10.0.8-h6,
PAN-OS 10.0.8-h5,
PAN-OS 10.0.8-h4,
PAN-OS 10.0.8-h3,
PAN-OS 10.0.8-h2,
PAN-OS 10.0.8-h1,
PAN-OS 10.0.8,
PAN-OS 10.0.7,
PAN-OS 10.0.6,
PAN-OS 10.0.5,
PAN-OS 10.0.4,
PAN-OS 10.0.3,
PAN-OS 10.0.2,
PAN-OS 10.0.1,
PAN-OS 10.0.0,
PAN-OS 10.0,
PAN-OS 9.1.13,
PAN-OS 9.1.12-h3,
PAN-OS 9.1.12-h2,
PAN-OS 9.1.12-h1,
PAN-OS 9.1.12,
PAN-OS 9.1.11-h3,
PAN-OS 9.1.11-h2,
PAN-OS 9.1.11-h1,
PAN-OS 9.1.11,
PAN-OS 9.1.10,
PAN-OS 9.1.9,
PAN-OS 9.1.8,
PAN-OS 9.1.7,
PAN-OS 9.1.6,
PAN-OS 9.1.5,
PAN-OS 9.1.4,
PAN-OS 9.1.3-h1,
PAN-OS 9.1.3,
PAN-OS 9.1.2-h1,
PAN-OS 9.1.2,
PAN-OS 9.1.1,
PAN-OS 9.1.0-h3,
PAN-OS 9.1.0-h2,
PAN-OS 9.1.0-h1,
PAN-OS 9.1.0,
PAN-OS 9.1,
PAN-OS 9.0.16,
PAN-OS 9.0.15,
PAN-OS 9.0.14-h4,
PAN-OS 9.0.14-h3,
PAN-OS 9.0.14-h2,
PAN-OS 9.0.14-h1,
PAN-OS 9.0.14,
PAN-OS 9.0.13,
PAN-OS 9.0.12,
PAN-OS 9.0.11,
PAN-OS 9.0.10,
PAN-OS 9.0.9-h1,
PAN-OS 9.0.9,
PAN-OS 9.0.8,
PAN-OS 9.0.7,
PAN-OS 9.0.6,
PAN-OS 9.0.5,
PAN-OS 9.0.4,
PAN-OS 9.0.3-h3,
PAN-OS 9.0.3-h2,
PAN-OS 9.0.3-h1,
PAN-OS 9.0.3,
PAN-OS 9.0.2-h4,
PAN-OS 9.0.2-h3,
PAN-OS 9.0.2-h2,
PAN-OS 9.0.2-h1,
PAN-OS 9.0.2,
PAN-OS 9.0.1,
PAN-OS 9.0.0,
PAN-OS 9.0,
PAN-OS 8.1.22,
PAN-OS 8.1.21-h1,
PAN-OS 8.1.21,
PAN-OS 8.1.20-h1,
PAN-OS 8.1.20,
PAN-OS 8.1.19,
PAN-OS 8.1.18,
PAN-OS 8.1.17,
PAN-OS 8.1.16,
PAN-OS 8.1.15-h3,
PAN-OS 8.1.15-h2,
PAN-OS 8.1.15-h1,
PAN-OS 8.1.15,
PAN-OS 8.1.14-h2,
PAN-OS 8.1.14-h1,
PAN-OS 8.1.14,
PAN-OS 8.1.13,
PAN-OS 8.1.12,
PAN-OS 8.1.11,
PAN-OS 8.1.10,
PAN-OS 8.1.9-h4,
PAN-OS 8.1.9-h3,
PAN-OS 8.1.9-h2,
PAN-OS 8.1.9-h1,
PAN-OS 8.1.9,
PAN-OS 8.1.8-h5,
PAN-OS 8.1.8-h4,
PAN-OS 8.1.8-h3,
PAN-OS 8.1.8-h2,
PAN-OS 8.1.8-h1,
PAN-OS 8.1.8,
PAN-OS 8.1.7,
PAN-OS 8.1.6-h2,
PAN-OS 8.1.6-h1,
PAN-OS 8.1.6,
PAN-OS 8.1.5,
PAN-OS 8.1.4,
PAN-OS 8.1.3,
PAN-OS 8.1.2,
PAN-OS 8.1.1,
PAN-OS 8.1.0,
PAN-OS 8.1,
GlobalProtect App,
Cortex XDR AgentPalo Alto Networks 2022-03-31T02:30:00.000Z CVE-2022-0778 Impact of the OpenSSL Infinite Loop Vulnerability CVE-2022-0778 7.5 HIGH CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H MITRE CVE The Palo Alto Networks Product Security Assurance team is evaluating the OpenSSL infinite loop vulnerability (CVE-2022-0778) as it relates to our products.
This vulnerability causes the OpenSSL library to enter an infinite loop when parsing an invalid certificate and can result in a Denial-of-Service (DoS) to the application. An attacker does not need a verified certificate to exploit this vulnerability because parsing a bad certificate triggers the infinite loop before the verification process is completed.
The Cortex XSOAR product is not impacted by this vulnerability. However, PAN-OS, GlobalProtect app, and Cortex XDR agent software contain a vulnerable version of the OpenSSL library and product availability is impacted by this vulnerability. For PAN-OS software, this includes both hardware and virtual firewalls and Panorama appliances as well as Prisma Access customers. This vulnerability has reduced severity on Cortex XDR agent and Global Protect app as successful exploitation requires an attacker-in-the-middle attack (MITM): 5.9 Medium (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H).
We are working diligently on fixes to remove the vulnerable code from our PAN-OS, GlobalProtect app, and Cortex XDR agent software. The fixed versions for hotfixes and other product upgrades will be updated in this advisory as soon as possible.
Configuration parameters
url— Default URL for PAN-OS advisories websitefetch_product_name— Fetch indicator product namefeed— Fetch indicatorsfeedReputation— Indicator ReputationfeedReliability— Source Reliability (required)feedExpirationPolicy—feedExpirationInterval—feedFetchInterval— Feed Fetch IntervalfeedBypassExclusionList— Bypass exclusion listfeedTags— Tagstlp_color— Traffic Light Protocol Color
Commands (1)
-
pan-advisories-get-advisoriesGets all the advisories for the given product.
import json import os from unittest.mock import patch from pathlib import Path import pytest from PaloAltoNetworksSecurityAdvisories import Client, fetch_indicators, get_advisories, advisory_to_indicator def util_load_json(path: str) -> dict: return json.loads(Path(path).read_text()) BASE_URL = "https://security.paloaltonetworks.com/api/v1" # Set envvar if you want to run integration tests. RUN_INTEGRATION_TESTS = os.getenv("INTEGRATION_TESTS") ClIENT = Client(base_url=BASE_URL) def test_client_get_products(): """Integration test; /api/v1/products""" if not RUN_INTEGRATION_TESTS: pytest.skip("Integration tests disabled.") result = ClIENT.get_products() assert result.get("success") is True assert isinstance(result.get("data"), list) def test_client_get_pan_os_advisories(): """Integration test; /api/v1/products""" if not RUN_INTEGRATION_TESTS: pytest.skip("Integration tests disabled.") result = ClIENT.get_advisories("PAN-OS", {}) assert result.get("success") is True assert isinstance(result.get("data"), list) result = ClIENT.get_advisories("PAN-OS", {"sort": "-cvss"}) assert result.get("data")[0].get("impact").get("cvss").get("baseScore") == 10 result = ClIENT.get_advisories("PAN-OS", {"q": '"CVE-2021-3056"'}) assert len(result.get("data")) == 1 @patch("PaloAltoNetworksSecurityAdvisories.Client.get_advisories") def test_get_advisories_command(patched_get_advisories): patched_get_advisories.return_value = util_load_json("test_data/advisories.json") result = get_advisories(ClIENT, "PANOS") assert result assert len(result.raw_response) == 3 @patch("PaloAltoNetworksSecurityAdvisories.Client.get_advisories") def test_fetch_indicators_command(patched_get_advisories): patched_get_advisories.return_value = util_load_json("test_data/advisories.json") result = fetch_indicators(ClIENT, "PANOS") assert result[0].get("value") assert result[0].get("type") assert result[0].get("rawJSON") for _field, field_value in result[0].get("fields").items(): assert field_value # Tests to cover CVE extraction issue. This test ensures the data which is expected in the CVE information is correct and # present. Fields effected are: cvss_score, cvss_severity, cvss_vector_string assert result[0].get("fields", {}).get("cvss", 0.0) == 9.3 assert result[0].get("fields", {}).get("cvssscore", 0.0) == 9.3 assert result[0].get("fields", {}).get("cvssvector", "NONE") == ( "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:N/SA:N/E:A/AU:N/R:U/V:C/RE:H/U:Red" ) assert result[0].get("fields", {}).get("cvssversion", "NONE") == "4.0" def test_advisory_to_indicator() -> None: """ Test the function advisory_to_indicator. Given: A mock data loaded from "test_data/advisories4.json" When: The function advisory_to_indicator is called with the response from the mock data Then: The function should return a dictionary with: - "value" key equal to "CVE-2023-38802" - "type" key equal to "CVE" - "fields" key equal to the "fields" key in the "excepted_response" of the mock data """ mock_data = util_load_json("test_data/advisories4.json") result = advisory_to_indicator(mock_data["response"]) assert result["value"] == "CVE-2024-0012" assert result["type"] == "CVE" assert result["fields"] == mock_data["excepted_response"]["fields"]