View the vulnerabilities on a firewall according to PAN-OS version and enabled
features.
| Where Can I Use This? | What Do I Need? |
Strata™ Cloud Manager shows you which vulnerabilities affect a given firewall and
PAN-OS version to help you decide whether you should upgrade. Common Vulnerabilities
and Exposures (CVE) incidents in Strata™ Cloud Manager alert you to known
vulnerabilities on your managed devices. This capability is a feature-based
vulnerability detection. Strata Cloud Manager only alerts you about firewalls that
are potentially vulnerable to a disclosed CVE because they are running the
vulnerable software version and have enabled the affected feature on the device. For
example, if a disclosed vulnerability affects GlobalProtect and you have not enabled
GlobalProtect® on a firewall, Strata Cloud Manager does not create an incident for
that firewall even if its PAN-OS version is potentially vulnerable. For this
capability, Strata Cloud Manager analyzes the enabled features to determine which
devices are impacted by the CVE.
CVE detection begins only after the Palo Alto Networks Product Security Incident
Response Team (PSIRT) publicly discloses the vulnerability. Detections are triggered
by specific telemetry from the firewall and can take up to 24 hours to identify CVEs
across your entire deployment, depending on the local time zones of the firewalls.
This capability works for hardware and software NGFWs. Strata Cloud Manager does not
detect vulnerabilities on Prisma® Access.
If a device does not appear in a CVE alert, one of the following conditions
applies:
- The device is running a PAN-OS version that is not impacted by the
vulnerability.
- The PAN-OS feature on which the vulnerability is disclosed is not enabled on that
device.
- Strata Cloud Manager does not yet have the telemetry from the device to
make the determination.
Navigate to
Incidents >
Incidents and
select the
PAN-OS Known Vulnerability incident to see the
latest
security advisories impacting the firewall that raised
the incident. Select
Vulnerabilities in this PAN-OS version
to view the affected feature for a vulnerability in the
Feature
Affected column. This helps you decide whether to upgrade a
firewall based on the vulnerability and its impact on your enabled feature. If a CVE
is not associated with a feature, then the value under
Feature
Affected is blank. This type of CVE affects the firewall with the
specified model or version.
By default, the
PAN-OS Known Vulnerability incident shows all
of the vulnerabilities in the PAN-OS version on the device. However, if you
enabled Product Usage telemetry on the
firewall, you can choose to view only the vulnerabilities that affect the particular
firewall based on its enabled features. That way, you can better understand which
vulnerabilities are a concern for the firewall and make a more informed decision
about whether to upgrade.
You can also use the PAN-OS CVEs dashboard that shows you the
number of devices impacted by a specific vulnerability based on the features that
have been enabled on devices. Strata Cloud Manager analyzes the features that have
been enabled to determine the devices impacted by the CVE. The PAN-OS CVE
dashboard is an alternate view of this information and reflects the summarized data
in the Incidents list view.
The following task shows how to assess vulnerabilities that impact devices and
generate upgrade recommendations to fix the vulnerabilities.