CyberICT

CVE-2024-3393

Palo Alto Networks · Published December 27, 2024

CVSS v3.1

HIGH
Patch availableGet patch

Description

A Denial of Service vulnerability in the DNS Security feature of Palo Alto Networks PAN-OS software allows an unauthenticated attacker to send a malicious packet through the data plane of the firewall that reboots the firewall. Repeated attempts to trigger this condition will cause the firewall to enter maintenance mode.

Affected Products

  • PAN OS <= 11.1.1
  • PAN OS < 11.2.3
  • PAN OS
  • Prisma Access

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H