PAN-SA-2016-0008MediumDisclosed before NVD

PAN-SA-2016-0008 PAN-OS API denial of service

Published
June 27, 2016
Last Modified
June 27, 2016

📋 Description

Palo Alto Networks firewalls offer an API to query and modify the configuration of the device. While access to this API is protected by the use of an API key, an issue was recently identified leading to a potential unauthenticated denial of service attack. (Ref #91728) The API is hosted on a dedicated management interface and, while this issue can result in a DoS attack of the API, it doesn’t compromise the security functionality of the device. This issue affects PAN-OS 7.0.1 to PAN-OS 7.0.7

🎯 Affected products1

  • PAN-OS

✅ Remediation

PAN-OS 7.0.8 and later Workarounds and mitigations: Exploitation of this issue is only available to personnel with access to the management interface on the device. Palo Alto Networks recommends the following best practice implementation: deploy the management interface on an out-of-band network and separate from inline traffic processing.

🔗 References (1)