HIGH

CVE-2024-3393

Paloaltonetworks Pan Os 2024-12-27 CVSS v3.1
CVSS
7.5
KEV

Description

A Denial of Service vulnerability in the DNS Security feature of Palo Alto Networks PAN-OS software allows an unauthenticated attacker to send a malicious packet through the data plane of the firewall that reboots the firewall. Repeated attempts to trigger this condition will cause the firewall to enter maintenance mode.

Summary dbcve.org

A Denial of Service vulnerability exists in the DNS Security feature of Palo Alto Networks PAN-OS software. An unauthenticated attacker can send a malicious packet through the firewall's data plane, causing an immediate reboot. Repeated exploitation forces the firewall into maintenance mode, resulting in sustained service disruption.

Mitigation

Apply the relevant PAN-OS security update when released by Palo Alto Networks. Consider disabling DNS Security or implementing network-level filtering to block malicious DNS packets until the patch can be applied.

Weakness (CWE)

CWE-754

EPSS Score

28.41%
Probability of exploitation in next 30 days
98.1th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE