CVE-2022-0028 | PAN-OS: Reflected Amplification Denial-of-Service (DoS) Vulnerability in URL Filtering

Exp

A PAN-OS URL filtering policy misconfiguration could allow a network-based attacker to conduct reflected and amplified TCP denial-of-service (RDoS) attacks. The DoS attack would appear to originate from a Palo Alto Networks PA-Series (hardware), VM-Series (virtual) and CN-Series (container) firewall against an attacker-specified target. To be misused by an external attacker, the firewall configuration must have a URL filtering profile with one or more blocked categories assigned to a source zone that has an external facing interface. This configuration is not typical for URL filtering and, if set, is likely unintended by the administrator. If exploited, this issue would not impact the confidentiality, integrity, or availability of our products. However, the resulting denial-of-service (DoS) attack may help obfuscate the identity of the attacker and implicate the firewall as the source of the attack. We have taken prompt action to address this issue in our PAN-OS software. All software updates for this issue are expected to be released no later than the week of August 15, 2022. This issue does not impact Panorama M-Series or Panorama virtual appliances. This issue has been resolved for all Cloud NGFW and Prisma Access customers and no additional action is required from them.

Published: 2022-08-10 Last update: 2025-11-04 Assigner: [email protected] Source: [email protected]

Conclusion & alert: CVE-2022-0028 is rated Critical Active Threat (90.6/100): CVSS High severity, with medium exploitation likelihood (EPSS 4.68%). Core evidence: CISA KEV confirms active exploitation (added 2022-08-22) affecting Palo Alto Networks / PAN-OS. a weakness (CWE-406) Unauthenticated remote administrative access may be possible. Mandatory action: The CISA remediation deadline has passed—treat as an emergency patch priority.

Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.

CISA KEV Record for CVE-2022-0028

Name: Palo Alto Networks PAN-OS Reflected Amplification Denial-of-Service Vulnerability · CISA KEV detail

Exploit added: 2022-08-22

Action due: 2022-09-12

Required action: Apply updates per vendor instructions.

Exploit prediction scoring system (EPSS) score for CVE-2022-0028

EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).

# Date Old EPSS score New EPSS score Delta (New - Old)
1 2026-05-27 4.81% 4.68% -0.12%
2 2026-05-22 4.68% 4.81% +0.12%
3 2025-12-28 4.68%

Full EPSS history (33 records total)

Common vulnerability scoring system (CVSS) metrics for CVE-2022-0028

CVSS metrics for this CVE.

Base score Version Severity Vector Exploitability Impact Score source
8.6 3.1 HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H Click to expand
Attack vector (AV:N)
Could be attacked over the internet or any normal routed network—not just someone sitting at the machine.
Attack complexity (AC:L)
Once they can reach the bug, pulling it off is straightforward—no weird race conditions or rare setup.
Privileges required (PR:N)
No account or special rights needed—anonymous or random user is enough.
User interaction (UI:N)
Nobody has to click “OK” or open a trap file; it can work without a victim helping.
Scope (S:C)
Breaking this can reach past the original component and bite other resources—bigger blast radius.
Confidentiality (C:N)
Doesn’t really leak secrets in a meaningful way.
Integrity (I:N)
Data isn’t meaningfully altered or forged.
Availability (A:H)
Could take the service down hard or make it unusable for people who depend on it.
3.9 4.0 [email protected]
8.6 3.1 HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H Click to expand
Attack vector (AV:N)
Could be attacked over the internet or any normal routed network—not just someone sitting at the machine.
Attack complexity (AC:L)
Once they can reach the bug, pulling it off is straightforward—no weird race conditions or rare setup.
Privileges required (PR:N)
No account or special rights needed—anonymous or random user is enough.
User interaction (UI:N)
Nobody has to click “OK” or open a trap file; it can work without a victim helping.
Scope (S:C)
Breaking this can reach past the original component and bite other resources—bigger blast radius.
Confidentiality (C:N)
Doesn’t really leak secrets in a meaningful way.
Integrity (I:N)
Data isn’t meaningfully altered or forged.
Availability (A:H)
Could take the service down hard or make it unusable for people who depend on it.
3.9 4.0 [email protected]

Weakness enumeration for CVE-2022-0028

Affected software / configurations for CVE-2022-0028

Vendor Product Version Raw CPE
paloaltonetworks pan-os >= 8.1.0, < 8.1.23 cpe:2.3:o:paloaltonetworks:pan-os:*:*:*:*:*:*:*:*
paloaltonetworks pan-os >= 9.0.0, < 9.0.16 cpe:2.3:o:paloaltonetworks:pan-os:*:*:*:*:*:*:*:*
paloaltonetworks pan-os >= 9.1.0, < 9.1.14 cpe:2.3:o:paloaltonetworks:pan-os:*:*:*:*:*:*:*:*
paloaltonetworks pan-os >= 10.0.0, < 10.0.11 cpe:2.3:o:paloaltonetworks:pan-os:*:*:*:*:*:*:*:*
paloaltonetworks pan-os >= 10.1.0, < 10.1.6 cpe:2.3:o:paloaltonetworks:pan-os:*:*:*:*:*:*:*:*
paloaltonetworks pan-os >= 10.2.0, < 10.2.2 cpe:2.3:o:paloaltonetworks:pan-os:*:*:*:*:*:*:*:*
paloaltonetworks pan-os 8.1.23 cpe:2.3:o:paloaltonetworks:pan-os:8.1.23:-:*:*:*:*:*:*
paloaltonetworks pan-os 9.0.16 cpe:2.3:o:paloaltonetworks:pan-os:9.0.16:-:*:*:*:*:*:*
paloaltonetworks pan-os 9.0.16 cpe:2.3:o:paloaltonetworks:pan-os:9.0.16:h2:*:*:*:*:*:*
paloaltonetworks pan-os 9.1.14 cpe:2.3:o:paloaltonetworks:pan-os:9.1.14:-:*:*:*:*:*:*
paloaltonetworks pan-os 9.1.14 cpe:2.3:o:paloaltonetworks:pan-os:9.1.14:h1:*:*:*:*:*:*
paloaltonetworks pan-os 10.0.11 cpe:2.3:o:paloaltonetworks:pan-os:10.0.11:*:*:*:*:*:*:*
paloaltonetworks pan-os 10.1.6 cpe:2.3:o:paloaltonetworks:pan-os:10.1.6:*:*:*:*:*:*:*
paloaltonetworks pan-os 10.1.6 cpe:2.3:o:paloaltonetworks:pan-os:10.1.6:h3:*:*:*:*:*:*
paloaltonetworks pan-os 10.2.2 cpe:2.3:o:paloaltonetworks:pan-os:10.2.2:-:*:*:*:*:*:*
paloaltonetworks pan-os 10.2.2 cpe:2.3:o:paloaltonetworks:pan-os:10.2.2:h1:*:*:*:*:*:*

References for CVE-2022-0028

cvelogic Threat Intelligence