PAN-SA-2022-0007None

PAN-SA-2022-0007 Impact of OpenSSL 3.0 Vulnerability CVE-2022-3996

Published
December 23, 2022
Last Modified
December 23, 2022

🔗 CVE IDs covered (1)

📋 Description

The OpenSSL Project has published a vulnerability CVE-2022-3996 that affects OpenSSL versions 3.0.0 through 3.0.7 on December 13, 2022. Exploitation of this vulnerability can result in a denial of service to an impacted application on Windows systems. The Palo Alto Networks Product Security Assurance team has evaluated and confirmed that all products and services are not impacted by this vulnerability.

🎯 Affected products26

  • PAN-OS
  • Cortex XDR Agent
  • GlobalProtect App
  • Cortex XSOAR
  • WildFire Appliance (WF-500)
  • Expanse
  • Okyo Garde
  • Palo Alto Networks App for Splunk
  • Prisma Cloud Compute
  • Expedition Migration Tool
  • IoT Security
  • User-ID Agent
  • Exact Data Matching CLI
  • Bridgecrew
  • Cortex Xpanse
  • Enterprise Data Loss Prevention
  • Prisma SD-WAN (CloudGenix)
  • Prisma SD-WAN ION
  • SaaS Security
  • Cortex Data Lake
  • AutoFocus
  • WildFire Cloud
  • Prisma Cloud
  • Cloud NGFW
  • Prisma Access
  • Cortex XDR

✅ Remediation

No software updates are required at this time. NOTE: Cortex XDR Broker VM versions earlier than Cortex XDR Broker VM 17.4.1 contain an affected version of the OpenSSL 3.0 library but are not impacted. There are no scenarios in Cortex XDR Broker VM software that enable successful exploitation of these vulnerabilities. The OpenSSL 3.0 library has been removed from Cortex XDR Broker VM 17.4.1 and later versions for security assurance. Workarounds and mitigations: There are no known workarounds for this issue.

🔗 References (1)