
Will never not be amused by CVE-2013-5663. Palo took the same app awareness that most every other UTM in the market supported but put it front and center. As they self branded as Next Gen Firewall. Only fools configure their firewalls to all or block based on ports! Allow all ports! Block by application because our firewall is the only one that is aware of what traffic is actually passing over a given port! No, the other UTMs could do app identification. They just did not recommend it being used exclusively and across the board because it was twitchy and compute intensive. So anyway, Palo had a little issue with their app ID. To save on compute they cached their app determination. Extensively. Open a session to a destination IP with an allowed app. Get fingerprinted. Allowed. Then kill that session and reconnect with the protocol you really wanted to use that would intially have been blocked. The Palo checks its cache, sees it already did the heavy lifting and allows the traffic. Why would you want to recheck a new TCP session?
Post summary
The text briefly mentions CVE-2013-5663 in the context of Palo Alto's application ID caching issue but provides no technical details, PoC, exploitation report, patch information, or false-positive claim.
