Summary
***Updated 04/08/2022***
The Spring-Projects team has released a blog in an effort to clear up confusion about the alleged deserialization RCE vulnerability. There are, however, vulnerabilities that have been patched and a Yara rule has been published. Please see the latest recommendations.
Threat Type
Vulnerability
Overview
***UPDATE #5, April 8, 2022***
A report from Chinese cybersecurity firm, Qihoo 360, has reported on the first confirmed case(s) of Spring4Shell being leveraged to gain access a
Summary
According to multiple sources an OpenSSL vulnerability in some Palo Alto appliances could be exploited to trigger a denial of service (DOS) condition. This vulnerability has been patched in OpenSSL but not all Palo Alto appliances.
Threat Type
Vulnerability
Overview
X-Force is tracking the disclosure of an OpenSSL vulnerability in some Palo Alto appliances that if exploited could lead to a denial of service (DOS) condition. In early March of 2022, updates were released by OpenSSL to address CVE-20