CVE-2022-0028: Palo Alto PAN-OS URL-filtering misconfiguration enabling reflected DoS
The short version: CVE-2022-0028 is a URL-filtering policy misconfiguration in PAN-OS that a network-based attacker can abuse to launch reflected, amplified TCP denial-of-service (RDoS) attacks — the traffic appears to originate from your Palo Alto firewall and is aimed at a target the attacker picks. It doesn't breach your firewall; it turns it into a weapon pointed at someone else. It's in CISA's KEV catalog. Steady hands — fix the policy and patch.
At a glance
| Fact | Detail |
|---|---|
| Our severity take | High — your device is abused as a reflector, not breached (see below) |
| CVSS v3.1 (NVD) | 8.6 — High · AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H |
| CVSS (Palo Alto) | 8.6 — High |
| EPSS | ~2.13% · 79.85th percentile (2026-07-17) |
| In CISA KEV? | Yes — remediate by 2022-09-12 |
| Known exploited? | Yes — a reflected DoS attempt was identified by a service provider |
| Vulnerability type | CWE-406 insufficient control of network message volume (network amplification) → reflected/amplified TCP DoS |
| Requires authenticated session? | No — network-based, no authentication |
| Affected | PAN-OS 8.1 < 8.1.23-h1, 9.0 < 9.0.16-h3, 9.1 < 9.1.14-h4, 10.0 < 10.0.11-h1, 10.1 < 10.1.6-h6, 10.2 < 10.2.2-h2, with a vulnerable URL-filtering profile applied |
| Fixed in | PAN-OS 8.1.23-h1 · 9.0.16-h3 · 9.1.14-h4 · 10.0.11-h1 · 10.1.6-h6 · 10.2.2-h2 (and later) |
What you need to know
This one is different from most firewall CVEs: the victim isn't (directly) you. When a specific URL-filtering policy misconfiguration is present, an attacker can send traffic that the PA-Series, VM-Series, or CN-Series firewall reflects and amplifies toward a target of the attacker's choosing. The DoS appears to originate from your firewall.
- How they find it — internet-wide scanning surfaces exposed PAN-OS devices; the misconfiguration determines whether the reflection works.
- How they use it — they abuse your device as a reflector/amplifier in a TCP denial-of-service campaign against a third party.
- What it leads to — bandwidth and resource impact, and reputational exposure from attack traffic that carries your address — rather than a compromise of your data or configuration.
How serious we see it
High — and we'll say plainly why it isn't higher.
The base score is 8.6 (High) driven by availability with scope change, and it is KEV-listed and confirmed abused. But the honest real-world framing matters: this flaw does not give an attacker access to your firewall, your data, or your network. It lets them borrow your device to attack someone else. That's a genuine problem — bandwidth, resource strain, and your address on abuse reports — but it's a Moderate operational/reputational issue, not a breach. It's also fully in your hands: correct the URL-filtering policy and apply the fix.
Recommendations
Straight from Palo Alto's advisory and CISA:
- Patch now. Upgrade to PAN-OS 8.1.23-h1 / 9.0.16-h3 / 9.1.14-h4 / 10.0.11-h1 / 10.1.6-h6 / 10.2.2-h2 or later.
- Fix the URL-filtering policy. Ensure your URL-filtering profile follows Palo Alto's guidance so the reflection condition can't be triggered.
- Monitor for abuse. Watch for anomalous outbound TCP volume that could indicate your device being used as a reflector.
- Confirm your exposure first. Verify whether an affected PAN-OS build with a vulnerable URL-filtering configuration is reachable.
How BreachRisk sees it
BreachRisk discovers internet-facing Palo Alto devices from little more than your domain, fingerprints the PAN-OS product and version, and flags exposure tied to KEV-listed vulnerabilities like this one so it rises to the top of your results.
The continuous, outside-in view means the exposed device is already mapped and version-fingerprinted when you go to confirm whether the vulnerable URL-filtering configuration applies — so a "your firewall could be abused as a DoS reflector" finding lands as something you can act on, not a maybe.