Aller au contenu
Toutes les vulnérabilités
CVE-2024-3393KEV

PAN-OS: Firewall Denial of Service (DoS) in DNS Security Using a Specially Crafted Packet

Sévérité
Élevée7,5CVSS 3.1, Élevée
EPSS
28 %
Publiée
27 déc. 2024
Mise à jour
17 juin 2026

Description

Le titre, la description et les consignes de l’éditeur sont cités depuis les enregistrements sources (en anglais).

A Denial of Service vulnerability in the DNS Security feature of Palo Alto Networks PAN-OS software allows an unauthenticated attacker to send a malicious packet through the data plane of the firewall that reboots the firewall. Repeated attempts to trigger this condition will cause the firewall to enter maintenance mode.

Faiblesse : CWE-754

Exploitée activement

Ajoutée au catalogue CISA KEV le 30 déc. 2024

Date limite de remédiation fédérale : 20 janv. 2025

Action requise : Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Prédiction d’exploitation

Probabilité d’exploitation de 28 % dans les 30 prochains jours (percentile 98 %).

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Ce qu’indique la source, par branche

Versions comparées par Patcharo

Palo Alto Networks PAN-OSSource : Palo Alto Networks (CVE record)

BrancheAffectéesCorrigé en
11.2
>= 11.2.0, < 11.2.3
>= 11.2.0, < 11.2.3
11.2.3
11.2.3
11.1
>= 11.1.0, < 11.1.2-h16
>= 11.1.3, < 11.1.3-h13
>= 11.1.4, < 11.1.4-h7
11.1.2-h16
11.1.3-h13
11.1.4-h7
10.2
>= 10.2.8, < 10.2.8-h19
>= 10.2.9, < 10.2.9-h19
>= 10.2.10, < 10.2.10-h12
>= 10.2.11, < 10.2.11-h10
>= 10.2.12, < 10.2.12-h4
>= 10.2.13, < 10.2.13-h2
10.2.8-h19
10.2.9-h19
10.2.10-h12
10.2.11-h10
10.2.12-h4
10.2.13-h2
10.1
>= 10.1.14, < 10.1.14-h8
10.1.14-h8

Selon l’éditeur, les versions non listées ne sont pas affectées.

Contournement / Remédiation de l’éditeur

Contournement · PAN-OS

If your firewall running the vulnerable PAN-OS versions stops responding or reboots unexpectedly and you cannot immediately apply a fix, apply a workaround below based on your deployment. Unmanaged NGFWs, NGFW managed by Panorama, or Prisma Access managed by Panorama * For each Anti-spyware profile, navigate to Objects → Security Profiles → Anti-spyware → (select a profile) → DNS Policies → DNS Security. * Change the Log Severity to "none" for all configured DNS Security categories. * Commit the changes. Remember to revert the Log Severity settings once the fixes are applied. NGFW managed by Strata Cloud Manager (SCM) You can choose one of the following mitigation options: * Option 1: Disable DNS Security logging directly on each NGFW by following the PAN-OS steps above. * Option 2: Disable DNS Security logging across all NGFWs in your tenant by opening a support case https://support.pa…

Remédiation de l’éditeur · PAN-OS

This issue is fixed in PAN-OS 10.1.14-h8, PAN-OS 10.2.10-h12, PAN-OS 11.1.5, PAN-OS 11.2.3, and all later PAN-OS versions. Note: PAN-OS 11.0 reached the end of life (EOL) on November 17, 2024, so we do not intend to provide a fix for this release. Prisma Access customers using DNS Security with affected PAN-OS versions should apply one of the workarounds provided below. We will perform upgrades in two phases for impacted customers on the weekends of January 3rd and January 10th. You can request an expedited Prisma Access upgrade to the latest PAN-OS version by opening a support case https://support.paloaltonetworks.com/Support/Index . In addition, to provide the most seamless upgrade path for our customers, we are making fixes available for other TAC-preferred and commonly deployed maintenance releases. ​​Additional PAN-OS 11.1 fixes: * 11.1.2-h16 * 11.1.3-h13 * 11.1.4-h7 * 11.1.5 Addit…

Références

Provenance

Chaque information de cette page provient des sources ci-dessous. Rien n’est rédigé par une IA.

Palo Alto Networks (CVE record)
Palo Alto Networks (CVE record) · 27 sept. 2026, 23:46 UTC · Analyseur patcharo-cve5/1.1.0
CISA Known Exploited Vulnerabilities
CISA Known Exploited Vulnerabilities · 27 sept. 2026, 23:42 UTC · Analyseur patcharo-kev/1.0.0
NVD
NVD · 27 sept. 2026, 23:44 UTC · Analyseur patcharo-nvd/1.0.0
FIRST EPSS
FIRST EPSS · 27 sept. 2026, 23:46 UTC · Analyseur patcharo-epss/1.0.0

Dernière vérification : 28 sept. 2026, 02:31 UTC