PAN-OS: Firewall Denial of Service (DoS) in DNS Security Using a Specially Crafted Packet
- Sévérité
- Élevée7,5CVSS 3.1, Élevée
- EPSS
- 28 %
- Publiée
- 27 déc. 2024
- Mise à jour
- 17 juin 2026
Description
Le titre, la description et les consignes de l’éditeur sont cités depuis les enregistrements sources (en anglais).
A Denial of Service vulnerability in the DNS Security feature of Palo Alto Networks PAN-OS software allows an unauthenticated attacker to send a malicious packet through the data plane of the firewall that reboots the firewall. Repeated attempts to trigger this condition will cause the firewall to enter maintenance mode.
Faiblesse : CWE-754
Exploitée activement
Ajoutée au catalogue CISA KEV le 30 déc. 2024
Date limite de remédiation fédérale : 20 janv. 2025
Action requise : Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Prédiction d’exploitation
Probabilité d’exploitation de 28 % dans les 30 prochains jours (percentile 98 %).
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Ce qu’indique la source, par branche
Versions comparées par Patcharo
Palo Alto Networks PAN-OSSource : Palo Alto Networks (CVE record)
| Branche | Affectées | Corrigé en |
|---|---|---|
| 11.2 | >= 11.2.0, < 11.2.3 >= 11.2.0, < 11.2.3 | 11.2.3 11.2.3 |
| 11.1 | >= 11.1.0, < 11.1.2-h16 >= 11.1.3, < 11.1.3-h13 >= 11.1.4, < 11.1.4-h7 | 11.1.2-h16 11.1.3-h13 11.1.4-h7 |
| 10.2 | >= 10.2.8, < 10.2.8-h19 >= 10.2.9, < 10.2.9-h19 >= 10.2.10, < 10.2.10-h12 >= 10.2.11, < 10.2.11-h10 >= 10.2.12, < 10.2.12-h4 >= 10.2.13, < 10.2.13-h2 | 10.2.8-h19 10.2.9-h19 10.2.10-h12 10.2.11-h10 10.2.12-h4 10.2.13-h2 |
| 10.1 | >= 10.1.14, < 10.1.14-h8 | 10.1.14-h8 |
Selon l’éditeur, les versions non listées ne sont pas affectées.
Contournement / Remédiation de l’éditeur
Contournement · PAN-OS
If your firewall running the vulnerable PAN-OS versions stops responding or reboots unexpectedly and you cannot immediately apply a fix, apply a workaround below based on your deployment. Unmanaged NGFWs, NGFW managed by Panorama, or Prisma Access managed by Panorama * For each Anti-spyware profile, navigate to Objects → Security Profiles → Anti-spyware → (select a profile) → DNS Policies → DNS Security. * Change the Log Severity to "none" for all configured DNS Security categories. * Commit the changes. Remember to revert the Log Severity settings once the fixes are applied. NGFW managed by Strata Cloud Manager (SCM) You can choose one of the following mitigation options: * Option 1: Disable DNS Security logging directly on each NGFW by following the PAN-OS steps above. * Option 2: Disable DNS Security logging across all NGFWs in your tenant by opening a support case https://support.pa…
Remédiation de l’éditeur · PAN-OS
This issue is fixed in PAN-OS 10.1.14-h8, PAN-OS 10.2.10-h12, PAN-OS 11.1.5, PAN-OS 11.2.3, and all later PAN-OS versions. Note: PAN-OS 11.0 reached the end of life (EOL) on November 17, 2024, so we do not intend to provide a fix for this release. Prisma Access customers using DNS Security with affected PAN-OS versions should apply one of the workarounds provided below. We will perform upgrades in two phases for impacted customers on the weekends of January 3rd and January 10th. You can request an expedited Prisma Access upgrade to the latest PAN-OS version by opening a support case https://support.paloaltonetworks.com/Support/Index . In addition, to provide the most seamless upgrade path for our customers, we are making fixes available for other TAC-preferred and commonly deployed maintenance releases. Additional PAN-OS 11.1 fixes: * 11.1.2-h16 * 11.1.3-h13 * 11.1.4-h7 * 11.1.5 Addit…
Références
Provenance
Chaque information de cette page provient des sources ci-dessous. Rien n’est rédigé par une IA.
- Palo Alto Networks (CVE record)
- Palo Alto Networks (CVE record) · 27 sept. 2026, 23:46 UTC · Analyseur patcharo-cve5/1.1.0
- CISA Known Exploited Vulnerabilities
- CISA Known Exploited Vulnerabilities · 27 sept. 2026, 23:42 UTC · Analyseur patcharo-kev/1.0.0
- NVD
- NVD · 27 sept. 2026, 23:44 UTC · Analyseur patcharo-nvd/1.0.0
- FIRST EPSS
- FIRST EPSS · 27 sept. 2026, 23:46 UTC · Analyseur patcharo-epss/1.0.0
Dernière vérification : 28 sept. 2026, 02:31 UTC