PT-2024-9866 · Palo Alto Networks · Pan-Os+1
Published
2024-12-27
·
Updated
2026-01-16
·
CVE-2024-3393
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L |
Name of the Vulnerable Software and Affected Versions:
Palo Alto Networks PAN-OS versions 10.X and 11.X, including Prisma Access.
Description:
A Denial of Service vulnerability in the DNS Security feature of Palo Alto Networks PAN-OS software allows an unauthenticated attacker to send a malicious packet through the data plane of the firewall that reboots the firewall. Repeated attempts to trigger this condition will cause the firewall to enter maintenance mode. The vulnerability is being actively exploited by hackers to disable firewall protections. Over 8,500 services are potentially vulnerable to this exploit, and more than 500 PAN-OS installations in RuNet are at risk, with 32 being potentially vulnerable and 218 hosts running an unsupported version of PAN-OS.
Recommendations:
Update to PAN-OS 10.1.14-h8 or later to fix the vulnerability.
As a temporary workaround, consider disabling the logging option of the "DNS Security" function until a patch is available.
Restrict access to the vulnerable module to minimize the risk of exploitation.
Avoid using the DNS Security feature until the issue is resolved.
Exploit
Fix
DoS
Improper Check for Exceptional Conditions
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Pan-Os
Prisma Access