PAN-SA-2023-0003 Informational Bulletin: Impact of MOVEit Vulnerabilities (CVE-2023-34362, CVE-2023-35036, CVE-2023-35708)
🔗 CVE IDs covered (3)
📋 Description
The Palo Alto Networks Product Security Assurance team has evaluated the recently disclosed critical Structured Query Language injection (SQLi) vulnerabilities (CVE-2023-34362, CVE-2023-35036, CVE-2023-35708) in the MOVEit Transfer product. Palo Alto Networks does not use MOVEit Transfer and is not impacted by these vulnerabilities. Protecting our customers is our highest priority. Palo Alto Networks and its Unit 42 threat research team are continuing to closely monitor all developments. You can find regular updates, as well as Palo Alto Networks product protections and interim guidance here: https://unit42.paloaltonetworks.com/threat-brief-moveit-cve-2023-34362/
🎯 Affected products26
- PAN-OS
- Cortex XDR Agent
- GlobalProtect App
- Cortex XSOAR
- WildFire Appliance (WF-500)
- Expanse
- Okyo Garde
- Palo Alto Networks App for Splunk
- Prisma Cloud Compute
- Expedition Migration Tool
- IoT Security
- User-ID Agent
- Exact Data Matching CLI
- Bridgecrew
- Cortex Xpanse
- Enterprise Data Loss Prevention
- Prisma SD-WAN (CloudGenix)
- Prisma SD-WAN ION
- SaaS Security
- Cortex Data Lake
- AutoFocus
- WildFire Cloud
- Prisma Cloud
- Cloud NGFW
- Prisma Access
- Cortex XDR
✅ Remediation
No software updates are required at this time. Workarounds and mitigations: Palo Alto Networks product protections for MOVEit Transfer vulnerabilities are captured in Unit 42's Threat Brief: https://unit42.paloaltonetworks.com/threat-brief-moveit-cve-2023-34362/. These mitigations reduce the risk of exploitation from known exploits.