Rewterz Threat Alert – MuddyWater APT – Active IOCs
March 11, 2022Rewterz Threat Advisory – CVE-2022-26878 – Linux Kernel VirtIO Bluetooth driver Vulnerability
March 14, 2022Rewterz Threat Alert – MuddyWater APT – Active IOCs
March 11, 2022Rewterz Threat Advisory – CVE-2022-26878 – Linux Kernel VirtIO Bluetooth driver Vulnerability
March 14, 2022Severity
Medium
Analysis Summary
CVE-2022-0022
Palo Alto Networks PAN-OS could allow a local authenticated attacker to obtain sensitive information, caused by the use of a weak cryptographic algorithm. By utilize password cracking attack techniques against accounts in normal (non-FIPS-CC) operational mode, an attacker could exploit this vulnerability to obtain password information, and use this information to launch further attacks against the affected system.
Impact
- Information Disclosure
Indicators Of Compromise
CVE
- CVE-2022-0022
Affected Vendors
- Palo Alto
Affected Products
- Palo Alto Networks PAN-OS 9.0.0
- Palo Alto Networks PAN-OS 8.1
- Palo Alto Networks PAN-OS 9.1.0
- Palo Alto Networks PAN-OS 10.0
Remediation
Refer to Palo Alto Networks Security Advisories for patch, upgrade or suggested workaround information.