>> All posts

CVE-2022-0028: Palo Alto PAN-OS URL-filtering misconfiguration enabling reflected DoS

The short version: CVE-2022-0028 is a URL-filtering policy misconfiguration in PAN-OS that a network-based attacker can abuse to launch reflected, amplified TCP denial-of-service (RDoS) attacks — the traffic appears to originate from your Palo Alto firewall and is aimed at a target the attacker picks. It doesn't breach your firewall; it turns it into a weapon pointed at someone else. It's in CISA's KEV catalog. Steady hands — fix the policy and patch.

At a glance

FactDetail
Our severity takeHigh — your device is abused as a reflector, not breached (see below)
CVSS v3.1 (NVD)8.6 — High · AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
CVSS (Palo Alto)8.6 — High
EPSS~2.13% · 79.85th percentile (2026-07-17)
In CISA KEV?Yes — remediate by 2022-09-12
Known exploited?Yes — a reflected DoS attempt was identified by a service provider
Vulnerability typeCWE-406 insufficient control of network message volume (network amplification) → reflected/amplified TCP DoS
Requires authenticated session?No — network-based, no authentication
AffectedPAN-OS 8.1 < 8.1.23-h1, 9.0 < 9.0.16-h3, 9.1 < 9.1.14-h4, 10.0 < 10.0.11-h1, 10.1 < 10.1.6-h6, 10.2 < 10.2.2-h2, with a vulnerable URL-filtering profile applied
Fixed inPAN-OS 8.1.23-h1 · 9.0.16-h3 · 9.1.14-h4 · 10.0.11-h1 · 10.1.6-h6 · 10.2.2-h2 (and later)

What you need to know

This one is different from most firewall CVEs: the victim isn't (directly) you. When a specific URL-filtering policy misconfiguration is present, an attacker can send traffic that the PA-Series, VM-Series, or CN-Series firewall reflects and amplifies toward a target of the attacker's choosing. The DoS appears to originate from your firewall.

  • How they find it — internet-wide scanning surfaces exposed PAN-OS devices; the misconfiguration determines whether the reflection works.
  • How they use it — they abuse your device as a reflector/amplifier in a TCP denial-of-service campaign against a third party.
  • What it leads to — bandwidth and resource impact, and reputational exposure from attack traffic that carries your address — rather than a compromise of your data or configuration.

How serious we see it

High — and we'll say plainly why it isn't higher.

The base score is 8.6 (High) driven by availability with scope change, and it is KEV-listed and confirmed abused. But the honest real-world framing matters: this flaw does not give an attacker access to your firewall, your data, or your network. It lets them borrow your device to attack someone else. That's a genuine problem — bandwidth, resource strain, and your address on abuse reports — but it's a Moderate operational/reputational issue, not a breach. It's also fully in your hands: correct the URL-filtering policy and apply the fix.

Recommendations

Straight from Palo Alto's advisory and CISA:

  1. Patch now. Upgrade to PAN-OS 8.1.23-h1 / 9.0.16-h3 / 9.1.14-h4 / 10.0.11-h1 / 10.1.6-h6 / 10.2.2-h2 or later.
  2. Fix the URL-filtering policy. Ensure your URL-filtering profile follows Palo Alto's guidance so the reflection condition can't be triggered.
  3. Monitor for abuse. Watch for anomalous outbound TCP volume that could indicate your device being used as a reflector.
  4. Confirm your exposure first. Verify whether an affected PAN-OS build with a vulnerable URL-filtering configuration is reachable.

How BreachRisk sees it

BreachRisk discovers internet-facing Palo Alto devices from little more than your domain, fingerprints the PAN-OS product and version, and flags exposure tied to KEV-listed vulnerabilities like this one so it rises to the top of your results.

The continuous, outside-in view means the exposed device is already mapped and version-fingerprinted when you go to confirm whether the vulnerable URL-filtering configuration applies — so a "your firewall could be abused as a DoS reflector" finding lands as something you can act on, not a maybe.

References

See your cyber risk, proven.