Answer in brief
CVE-2022-0028 records a High severity vulnerability in PAN-OS: Reflected Amplification Denial-of-Service (DoS) Vulnerability in URL Filtering. The current sources mark it as known exploited. The current feed maps paloaltonetworks/pan-os (generic), paloaltonetworks/pan-os (generic), paloaltonetworks/pan-os (generic), paloaltonetworks/pan-os (generic) and additional mapped packages. Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. Known-exploitation status makes exposure review time-sensitive. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps paloaltonetworks/pan-os (generic), paloaltonetworks/pan-os (generic), paloaltonetworks/pan-os (generic), paloaltonetworks/pan-os (generic) and additional mapped packages. Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| paloaltonetworks/pan-osgeneric | >=10.0.0 <10.0.11-h1 | 10.0.11-h1 |
| paloaltonetworks/pan-osgeneric | >=10.1.0 <10.1.6-h6 | 10.1.6-h6 |
| paloaltonetworks/pan-osgeneric | >=8.1.0 <8.1.23-h | 8.1.23-h |
| paloaltonetworks/pan-osgeneric | >=9.0.0 <9.0.16-h3 | 9.0.16-h3 |
| paloaltonetworks/pan-osgeneric | >=9.1.0 <9.1 < 9.1.14-h4 | 9.1 < 9.1.14-h4 |
| paloaltonetworks/pan-osgeneric | >=10.2.0 <10.2.2-h2 | 10.2.2-h2 |
| Palo Alto Networks/PAN-OSgeneric | >=8.1 <8.1.23-h1 || >=9.0 <9.0.16-h3 || >=9.1 <9.1.14-h4 || >=10.0 <10.0.11-h1 || >=10.1 <10.1.6-h6 || >=10.2 <10.2.2-h2 | 8.1.23-h1, 9.0.16-h3, 9.1.14-h4, 10.0.11-h1, 10.1.6-h6, 10.2.2-h2 |
Published upstream
Aug 10, 2022
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Oct 21, 2025
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
May 24, 2026
Added to CISA KEV
Aug 22, 2022
Evidence: source:kev:kev:kev:recordA PAN-OS URL filtering policy misconfiguration could allow a network-based attacker to conduct reflected and amplified TCP denial-of-service (RDoS) attacks. The DoS attack would appear to originate from a Palo Alto Networks PA-Series (hardware), VM-Series (virtual) and CN-Series (container) firewall against an attacker-specified target. To be misused by an external attacker, the firewall configuration must have a URL filtering profile with one or more blocked categories assigned to a source zone that has an external facing interface. This configuration is not typical for URL filtering and, if set, is likely unintended by the administrator. If exploited, this issue would not impact the confidentiality, integrity, or availability of our products. However, the resulting denial-of-service (DoS) attack may help obfuscate the identity of the attacker and implicate the firewall as the source of the attack. We have taken prompt action to address this issue in our PAN-OS software. All software updates for this issue are expected to be released no later than the week of August 15, 2022. This issue does not impact Panorama M-Series or Panorama virtual appliances. This issue has been resolved for all Cloud NGFW and Prisma Access customers and no additional action is required from them.
Quoted source text, attributed separately from HOL analysis.
Answer in brief
CVE-2022-0028 records a High severity vulnerability in PAN-OS: Reflected Amplification Denial-of-Service (DoS) Vulnerability in URL Filtering. The current sources mark it as known exploited. The current feed maps paloaltonetworks/pan-os (generic), paloaltonetworks/pan-os (generic), paloaltonetworks/pan-os (generic), paloaltonetworks/pan-os (generic) and additional mapped packages. Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. Known-exploitation status makes exposure review time-sensitive. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps paloaltonetworks/pan-os (generic), paloaltonetworks/pan-os (generic), paloaltonetworks/pan-os (generic), paloaltonetworks/pan-os (generic) and additional mapped packages. Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| paloaltonetworks/pan-osgeneric | >=10.0.0 <10.0.11-h1 | 10.0.11-h1 |
| paloaltonetworks/pan-osgeneric | >=10.1.0 <10.1.6-h6 | 10.1.6-h6 |
| paloaltonetworks/pan-osgeneric | >=8.1.0 <8.1.23-h | 8.1.23-h |
| paloaltonetworks/pan-osgeneric | >=9.0.0 <9.0.16-h3 | 9.0.16-h3 |
| paloaltonetworks/pan-osgeneric | >=9.1.0 <9.1 < 9.1.14-h4 | 9.1 < 9.1.14-h4 |
| paloaltonetworks/pan-osgeneric | >=10.2.0 <10.2.2-h2 | 10.2.2-h2 |
| Palo Alto Networks/PAN-OSgeneric | >=8.1 <8.1.23-h1 || >=9.0 <9.0.16-h3 || >=9.1 <9.1.14-h4 || >=10.0 <10.0.11-h1 || >=10.1 <10.1.6-h6 || >=10.2 <10.2.2-h2 | 8.1.23-h1, 9.0.16-h3, 9.1.14-h4, 10.0.11-h1, 10.1.6-h6, 10.2.2-h2 |
Published upstream
Aug 10, 2022
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Oct 21, 2025
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
May 24, 2026
Added to CISA KEV
Aug 22, 2022
Evidence: source:kev:kev:kev:recordA PAN-OS URL filtering policy misconfiguration could allow a network-based attacker to conduct reflected and amplified TCP denial-of-service (RDoS) attacks. The DoS attack would appear to originate from a Palo Alto Networks PA-Series (hardware), VM-Series (virtual) and CN-Series (container) firewall against an attacker-specified target. To be misused by an external attacker, the firewall configuration must have a URL filtering profile with one or more blocked categories assigned to a source zone that has an external facing interface. This configuration is not typical for URL filtering and, if set, is likely unintended by the administrator. If exploited, this issue would not impact the confidentiality, integrity, or availability of our products. However, the resulting denial-of-service (DoS) attack may help obfuscate the identity of the attacker and implicate the firewall as the source of the attack. We have taken prompt action to address this issue in our PAN-OS software. All software updates for this issue are expected to be released no later than the week of August 15, 2022. This issue does not impact Panorama M-Series or Panorama virtual appliances. This issue has been resolved for all Cloud NGFW and Prisma Access customers and no additional action is required from them.
Quoted source text, attributed separately from HOL analysis.