CVE-2024-3393
Description
A Denial of Service vulnerability in the DNS Security feature of Palo Alto Networks PAN-OS software allows an unauthenticated attacker to send a malicious packet through the data plane of the firewall that reboots the firewall. Repeated attempts to trigger this condition will cause the firewall to enter maintenance mode.
Summary dbcve.org
A Denial of Service vulnerability exists in the DNS Security feature of Palo Alto Networks PAN-OS software. An unauthenticated attacker can send a malicious packet through the firewall's data plane, causing an immediate reboot. Repeated exploitation forces the firewall into maintenance mode, resulting in sustained service disruption.
Mitigation
Apply the relevant PAN-OS security update when released by Palo Alto Networks. Consider disabling DNS Security or implementing network-level filtering to block malicious DNS packets until the patch can be applied.