CVE-2022-0022 - CVE House
Back to Database
Status published Medium CVE-2022-0022

PAN-OS: Use of a Weak Cryptographic Algorithm for Stored Password Hashes

Vulnerability Description

Usage of a weak cryptographic algorithm in Palo Alto Networks PAN-OS software where the password hashes of administrator and local user accounts are not created with a sufficient level of computational effort, which allows for password cracking attacks on accounts in normal (non-FIPS-CC) operational mode. An attacker must have access to the account password hashes to take advantage of this weakness and can acquire those hashes if they are able to gain access to the PAN-OS software configuration. Fixed versions of PAN-OS software use a secure cryptographic algorithm for account password hashes. This issue does not impact Prisma Access firewalls. This issue impacts: PAN-OS 8.1 versions earlier than PAN-OS 8.1.21; All versions of PAN-OS 9.0; PAN-OS 9.1 versions earlier than PAN-OS 9.1.11; PAN-OS 10.0 versions earlier than PAN-OS 10.0.7.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2022-0022

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • Palo Alto Networks thanks an external security researcher for discovering and reporting this issue.

Affected Vendor

Palo Alto Networks

View all reports →

Affected Software

PAN-OS, Prisma Access
Vulnerable Versions:
10.1.*, 9.0.*, 10.2.*, 9.1, 8.1, 10.0, 3.0 Preferred, Innovation, 2.2 Preferred, 2.1 Preferred, Innovation

Timeline

Official Publish: March 9th, 2022
Last Modified: September 16th, 2024
Added to House: July 21st, 2026

CVSS Vectors

V3: CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N

Weaknesses (CWE)

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.