PAN-SA-2023-0001 Impact of OpenSSL Vulnerabilities Disclosed Feb 7, 2023
🔗 CVE IDs covered (8)
📋 Description
The Palo Alto Networks Product Security Assurance team has evaluated the OpenSSL vulnerabilities that were disclosed on February 7, 2023 (CVE-2023-0286, CVE-2022-4304, CVE-2022-4203, CVE-2023-0215, CVE-2022-4450, CVE-2023-0216, CVE-2023-0217, and CVE-2023-0401) as it relates to our products. At this time, there are no demonstrated scenarios that enable successful exploitation of these vulnerabilities in our products.
🎯 Affected products26
- PAN-OS
- Cortex XDR Agent
- GlobalProtect App
- Cortex XSOAR
- WildFire Appliance (WF-500)
- Expanse
- Okyo Garde
- Palo Alto Networks App for Splunk
- Prisma Cloud Compute
- Expedition Migration Tool
- IoT Security
- User-ID Agent
- Exact Data Matching CLI
- Bridgecrew
- Cortex Xpanse
- Enterprise Data Loss Prevention
- Prisma SD-WAN (CloudGenix)
- Prisma SD-WAN ION
- SaaS Security
- Cortex Data Lake
- AutoFocus
- WildFire Cloud
- Prisma Cloud
- Cloud NGFW
- Prisma Access
- Cortex XDR
✅ Remediation
Out of an abundance of caution, OpenSSL has been upgraded or patched in the following products to address the underlying code defects that result in these vulnerabilities: For PAN-OS, these changes will be available in PAN-OS 10.2.5, PAN-OS 11.0.2, and all later PAN-OS versions. For GlobalProtect app, these changes will be available in GlobalProtect app 6.0.6 and later GlobalProtect app versions.