{"id":327604,"date":"2022-08-23T05:53:39","date_gmt":"2022-08-23T07:53:39","guid":{"rendered":"https:\/\/teknomers.com\/fr\/la-cisa-met-en-garde-contre-lexploitation-active-de-la-vulnerabilite-pan-os-de-palo-alto-networks\/"},"modified":"2022-08-23T05:53:41","modified_gmt":"2022-08-23T07:53:41","slug":"la-cisa-met-en-garde-contre-lexploitation-active-de-la-vulnerabilite-pan-os-de-palo-alto-networks","status":"publish","type":"post","link":"https:\/\/teknomers.com\/fr\/la-cisa-met-en-garde-contre-lexploitation-active-de-la-vulnerabilite-pan-os-de-palo-alto-networks\/","title":{"rendered":"La CISA met en garde contre l&#8217;exploitation active de la vuln\u00e9rabilit\u00e9 PAN-OS de Palo Alto Networks"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both\"><\/div>\n<p>L&#8217;Agence am\u00e9ricaine de cybers\u00e9curit\u00e9 et de s\u00e9curit\u00e9 des infrastructures (CISA) lundi <a rel=\"nofollow noopener\" href=\"https:\/\/www.cisa.gov\/uscert\/ncas\/current-activity\/2022\/08\/22\/cisa-adds-one-known-exploited-vulnerabilities-catalog\" target=\"_blank\">ajout\u00e9e<\/a> une faille de s\u00e9curit\u00e9 affectant Palo Alto Networks PAN-OS \u00e0 son <a rel=\"nofollow noopener\" href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog\" target=\"_blank\">Catalogue des vuln\u00e9rabilit\u00e9s exploit\u00e9es connues<\/a>sur la base de preuves d&#8217;exploitation active.<\/p>\n<p>La vuln\u00e9rabilit\u00e9 de haute gravit\u00e9, suivie comme <a rel=\"nofollow noopener\" href=\"https:\/\/security.paloaltonetworks.com\/CVE-2022-0028\" target=\"_blank\">CVE-2022-0028<\/a> (score CVSS\u00a0: 8,6), est une mauvaise configuration de la politique de filtrage d&#8217;URL qui pourrait permettre \u00e0 un attaquant distant non authentifi\u00e9 de mener des attaques par d\u00e9ni de service (DoS) TCP r\u00e9fl\u00e9chies et amplifi\u00e9es.<\/p>\n<div class=\"ad_two clear\"><a rel=\"nofollow noopener\" href=\"https:\/\/go.thn.li\/strike-d\" target=\"_blank\" title=\"DevOps backupy\"><img decoding=\"async\" alt=\"La cyber-s\u00e9curit\u00e9\" class=\"lazyload\" loading=\"lazy\" src=\"https:\/\/teknomers.com\/fr\/wp-content\/uploads\/2022\/08\/Une-nouvelle-attaque-Air-Gap-utilise-le-canal-secret-ultrasonique-du.png\" width=\"300\" height=\"250\" \/><\/a><\/div>\n<p>\u00ab S&#8217;il \u00e9tait exploit\u00e9, ce probl\u00e8me n&#8217;aurait aucune incidence sur la confidentialit\u00e9, l&#8217;int\u00e9grit\u00e9 ou la disponibilit\u00e9 de nos produits \u00bb, a d\u00e9clar\u00e9 Palo Alto Networks dans une alerte.  &#8220;Cependant, l&#8217;attaque par d\u00e9ni de service (DoS) qui en r\u00e9sulte peut aider \u00e0 masquer l&#8217;identit\u00e9 de l&#8217;attaquant et impliquer le pare-feu comme source de l&#8217;attaque.<\/p>\n<p>La faiblesse affecte les versions de produit suivantes et a \u00e9t\u00e9 corrig\u00e9e dans le cadre des mises \u00e0 jour publi\u00e9es ce mois-ci\u00a0:<\/p>\n<ul>\n<li>Pan OS 10.2 (version &lt; 10.2.2-h2)<\/li>\n<li>Pan OS 10.1 (version &lt; 10.1.6-h6)<\/li>\n<li>Pan OS 10.0 (version &lt; 10.0.11-h1)<\/li>\n<li>Pan OS 9.1 (version &lt; 9.1.14-h4)<\/li>\n<li>PAN-OS 9.0 (version &lt; 9.0.16-h3) et<\/li>\n<li>Pan OS 8.1 (version &lt; 8.1.23-h1)<\/li>\n<\/ul>\n<div class=\"ad_two clear\"><a rel=\"nofollow noopener\" href=\"https:\/\/go.thn.li\/crowd-mid-d\" target=\"_blank\" title=\"CyberSecurity\"><img decoding=\"async\" alt=\"La cyber-s\u00e9curit\u00e9\" class=\"lazyload\" loading=\"lazy\" src=\"https:\/\/teknomers.com\/fr\/wp-content\/uploads\/2022\/08\/1661231965_829_Une-nouvelle-attaque-Air-Gap-utilise-le-canal-secret-ultrasonique-du.png\" width=\"728\" height=\"90\" \/><\/a><\/div>\n<p>Le fabricant d&#8217;\u00e9quipements r\u00e9seau a d\u00e9clar\u00e9 avoir d\u00e9couvert la vuln\u00e9rabilit\u00e9 apr\u00e8s avoir \u00e9t\u00e9 inform\u00e9 que des pare-feu sensibles de diff\u00e9rents fournisseurs, y compris Palo Alto Networks, \u00e9taient utilis\u00e9s dans le cadre d&#8217;une tentative d&#8217;attaque par d\u00e9ni de service r\u00e9fl\u00e9chi (RDoS).<\/p>\n<p>\u00c0 la lumi\u00e8re de l&#8217;exploitation active, les clients des produits concern\u00e9s sont invit\u00e9s \u00e0 appliquer les correctifs appropri\u00e9s pour att\u00e9nuer les menaces potentielles.  Les agences du Pouvoir ex\u00e9cutif civil f\u00e9d\u00e9ral (FCEB) sont mandat\u00e9es pour mettre \u00e0 jour la derni\u00e8re version d&#8217;ici le 12 septembre 2022.<\/p>\n<p><\/p>\n<\/div>\n<p><br \/>\n<br \/><a href=\"https:\/\/thehackernews.com\/2022\/08\/cisa-warns-of-active-exploitation-of.html\" rel=\"nofollow noopener\" target=\"_blank\">ttn-fr-57<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>L&#8217;Agence am\u00e9ricaine de cybers\u00e9curit\u00e9 et de s\u00e9curit\u00e9 des infrastructures (CISA) lundi ajout\u00e9e une faille de s\u00e9curit\u00e9 affectant Palo Alto Networks PAN-OS \u00e0 son Catalogue des vuln\u00e9rabilit\u00e9s exploit\u00e9es connuessur la base de preuves d&#8217;exploitation active. La vuln\u00e9rabilit\u00e9 de haute gravit\u00e9, suivie comme CVE-2022-0028 (score CVSS\u00a0: 8,6), est une mauvaise configuration de la politique de filtrage d&#8217;URL [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":327605,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6],"tags":[9261,79745,4805,4168,841,4158,4165,4161,525,4157,4159,4171,4170,14592,4167,4955,4160,79746,4163,4162,79744,69162,4172,4169,4166,3667,4164],"class_list":["post-327604","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-technologie","tag-active","tag-alto","tag-cisa","tag-comment-pirater","tag-contre","tag-cyber-actualites","tag-cyber-attaques","tag-cyber-mises-a-jour","tag-garde","tag-lactualite-de-la-cybersecurite","tag-lactualite-de-la-cybersecurite-aujourdhui","tag-lactualite-des-hackers","tag-la-securite-des-informations","tag-lexploitation","tag-logiciel-malveillant-de-ransomware","tag-met","tag-mises-a-jour-de-la-cybersecurite","tag-networks","tag-nouvelles-de-piratage","tag-nouvelles-de-pirates","tag-palo","tag-panos","tag-securite-informatique","tag-securite-internet","tag-violation-de-donnees","tag-vulnerabilite","tag-vulnerabilite-logicielle"],"_links":{"self":[{"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/posts\/327604","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/comments?post=327604"}],"version-history":[{"count":0,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/posts\/327604\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/media\/327605"}],"wp:attachment":[{"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/media?parent=327604"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/categories?post=327604"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/tags?post=327604"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}