Assess Vulnerabilities
Focus
Focus
Strata Cloud Manager

Assess Vulnerabilities

Table of Contents

Assess Vulnerabilities

View the vulnerabilities on a firewall according to PAN-OS version and enabled features.
Where Can I Use This?What Do I Need?
One of these:
Strata™ Cloud Manager shows you which vulnerabilities affect a given firewall and PAN-OS version to help you decide whether you should upgrade. Common Vulnerabilities and Exposures (CVE) incidents in Strata™ Cloud Manager alert you to known vulnerabilities on your managed devices. This capability is a feature-based vulnerability detection. Strata Cloud Manager only alerts you about firewalls that are potentially vulnerable to a disclosed CVE because they are running the vulnerable software version and have enabled the affected feature on the device. For example, if a disclosed vulnerability affects GlobalProtect and you have not enabled GlobalProtect® on a firewall, Strata Cloud Manager does not create an incident for that firewall even if its PAN-OS version is potentially vulnerable. For this capability, Strata Cloud Manager analyzes the enabled features to determine which devices are impacted by the CVE.
CVE detection begins only after the Palo Alto Networks Product Security Incident Response Team (PSIRT) publicly discloses the vulnerability. Detections are triggered by specific telemetry from the firewall and can take up to 24 hours to identify CVEs across your entire deployment, depending on the local time zones of the firewalls. This capability works for hardware and software NGFWs. Strata Cloud Manager does not detect vulnerabilities on Prisma® Access.
If a device does not appear in a CVE alert, one of the following conditions applies:
  • The device is running a PAN-OS version that is not impacted by the vulnerability.
  • The PAN-OS feature on which the vulnerability is disclosed is not enabled on that device.
  • Strata Cloud Manager does not yet have the telemetry from the device to make the determination.
Navigate to Incidents > Incidents and select the PAN-OS Known Vulnerability incident to see the latest security advisories impacting the firewall that raised the incident. Select Vulnerabilities in this PAN-OS version to view the affected feature for a vulnerability in the Feature Affected column. This helps you decide whether to upgrade a firewall based on the vulnerability and its impact on your enabled feature. If a CVE is not associated with a feature, then the value under Feature Affected is blank. This type of CVE affects the firewall with the specified model or version.
By default, the PAN-OS Known Vulnerability incident shows all of the vulnerabilities in the PAN-OS version on the device. However, if you enabled Product Usage telemetry on the firewall, you can choose to view only the vulnerabilities that affect the particular firewall based on its enabled features. That way, you can better understand which vulnerabilities are a concern for the firewall and make a more informed decision about whether to upgrade.
You can also use the PAN-OS CVEs dashboard that shows you the number of devices impacted by a specific vulnerability based on the features that have been enabled on devices. Strata Cloud Manager analyzes the features that have been enabled to determine the devices impacted by the CVE. The PAN-OS CVE dashboard is an alternate view of this information and reflects the summarized data in the Incidents list view.
The following task shows how to assess vulnerabilities that impact devices and generate upgrade recommendations to fix the vulnerabilities.
  1. From Strata Cloud Manager, navigate to Insights > POSTURE > PAN-OS CVEs.
  2. Expand a CVE to view the devices impacted by it.
  3. Select devices that you want to upgrade to fix the vulnerabilities.
  4. Generate Upgrade Recommendations.
  5. Click the newly generated report for the devices.
  6. Select one of the upgrade options to view details about New Features, PAN-OS Known Vulnerabilities, Changes of Behavior, and PAN-OS Known Issues
    You can Export the details in a CSV file and download it.