Skip to content
All vulnerabilities
CVE-2024-3393KEV

PAN-OS: Firewall Denial of Service (DoS) in DNS Security Using a Specially Crafted Packet

Severity
High7.5CVSS 3.1, High
EPSS
28%
Published
27 Dec 2024
Updated
17 Jun 2026

Description

Title, description and vendor guidance are quoted from the source records.

A Denial of Service vulnerability in the DNS Security feature of Palo Alto Networks PAN-OS software allows an unauthenticated attacker to send a malicious packet through the data plane of the firewall that reboots the firewall. Repeated attempts to trigger this condition will cause the firewall to enter maintenance mode.

Weakness: CWE-754

Known exploited

Added to CISA KEV on 30 Dec 2024

Federal remediation due date: 20 Jan 2025

Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Exploit prediction

28% probability of exploitation in the next 30 days (percentile 98%).

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

What the source states, per branch

Versions matched by Patcharo

Palo Alto Networks PAN-OSSource: Palo Alto Networks (CVE record)

BranchAffectedFixed in
11.2
>= 11.2.0, < 11.2.3
>= 11.2.0, < 11.2.3
11.2.3
11.2.3
11.1
>= 11.1.0, < 11.1.2-h16
>= 11.1.3, < 11.1.3-h13
>= 11.1.4, < 11.1.4-h7
11.1.2-h16
11.1.3-h13
11.1.4-h7
10.2
>= 10.2.8, < 10.2.8-h19
>= 10.2.9, < 10.2.9-h19
>= 10.2.10, < 10.2.10-h12
>= 10.2.11, < 10.2.11-h10
>= 10.2.12, < 10.2.12-h4
>= 10.2.13, < 10.2.13-h2
10.2.8-h19
10.2.9-h19
10.2.10-h12
10.2.11-h10
10.2.12-h4
10.2.13-h2
10.1
>= 10.1.14, < 10.1.14-h8
10.1.14-h8

Versions not listed are stated unaffected by the vendor.

Workaround / Vendor remediation

Workaround · PAN-OS

If your firewall running the vulnerable PAN-OS versions stops responding or reboots unexpectedly and you cannot immediately apply a fix, apply a workaround below based on your deployment. Unmanaged NGFWs, NGFW managed by Panorama, or Prisma Access managed by Panorama * For each Anti-spyware profile, navigate to Objects → Security Profiles → Anti-spyware → (select a profile) → DNS Policies → DNS Security. * Change the Log Severity to "none" for all configured DNS Security categories. * Commit the changes. Remember to revert the Log Severity settings once the fixes are applied. NGFW managed by Strata Cloud Manager (SCM) You can choose one of the following mitigation options: * Option 1: Disable DNS Security logging directly on each NGFW by following the PAN-OS steps above. * Option 2: Disable DNS Security logging across all NGFWs in your tenant by opening a support case https://support.pa…

Vendor remediation · PAN-OS

This issue is fixed in PAN-OS 10.1.14-h8, PAN-OS 10.2.10-h12, PAN-OS 11.1.5, PAN-OS 11.2.3, and all later PAN-OS versions. Note: PAN-OS 11.0 reached the end of life (EOL) on November 17, 2024, so we do not intend to provide a fix for this release. Prisma Access customers using DNS Security with affected PAN-OS versions should apply one of the workarounds provided below. We will perform upgrades in two phases for impacted customers on the weekends of January 3rd and January 10th. You can request an expedited Prisma Access upgrade to the latest PAN-OS version by opening a support case https://support.paloaltonetworks.com/Support/Index . In addition, to provide the most seamless upgrade path for our customers, we are making fixes available for other TAC-preferred and commonly deployed maintenance releases. ​​Additional PAN-OS 11.1 fixes: * 11.1.2-h16 * 11.1.3-h13 * 11.1.4-h7 * 11.1.5 Addit…

References

Provenance

Every fact on this page comes from the sources below. Nothing is written by an AI.

Palo Alto Networks (CVE record)
Palo Alto Networks (CVE record) · 27 Sept 2026, 23:46 UTC · Parser patcharo-cve5/1.1.0
CISA Known Exploited Vulnerabilities
CISA Known Exploited Vulnerabilities · 27 Sept 2026, 23:42 UTC · Parser patcharo-kev/1.0.0
NVD
NVD · 27 Sept 2026, 23:44 UTC · Parser patcharo-nvd/1.0.0
FIRST EPSS
FIRST EPSS · 27 Sept 2026, 23:46 UTC · Parser patcharo-epss/1.0.0

Last verified: 28 Sept 2026, 02:31 UTC