Aller au contenu
Toutes les vulnérabilités
CVE-2026-0287

PAN-OS: Denial of Service Vulnerabilities in Network Traffic Processing

Sévérité
Élevée7,5CVSS 3.1, Élevée
EPSS
0,62 %
Publiée
9 juil. 2026
Mise à jour
11 août 2026

Description

Le titre, la description et les consignes de l’éditeur sont cités depuis les enregistrements sources (en anglais).

Multiple denial of service vulnerabilities in Palo Alto Networks PAN-OS® software allow an unauthenticated attacker with network access to cause a denial of service (DoS) condition by sending specially crafted network traffic to or through a dataplane interface. Repeated attempts to trigger this condition result in the firewall entering maintenance mode. Panorama is not impacted by these vulnerabilities.

Faiblesse : CWE-754

Exploitée activement

Non listée dans CISA KEV lors de la dernière vérification.

Prédiction d’exploitation

Probabilité d’exploitation de 0,62 % dans les 30 prochains jours (percentile 48 %).

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Ce qu’indique la source, par branche

Versions comparées par Patcharo

Palo Alto Networks PAN-OSSource : Palo Alto Networks (CVE record)

BrancheAffectéesCorrigé en
12.1
>= 12.1.0, < 12.1.4-h8
>= 12.1.5, < 12.1.7-h2
12.1.4-h8
12.1.7-h2
11.2
>= 11.2.0, < 11.2.4-h20
>= 11.2.5, < 11.2.7-h18
>= 11.2.8, < 11.2.10-h12
>= 11.2.11, < 11.2.13
11.2.4-h20
11.2.7-h18
11.2.10-h12
11.2.13
11.1
>= 11.1.0, < 11.1.4-h35
>= 11.1.5, < 11.1.6-h35
>= 11.1.7, < 11.1.7-h8
>= 11.1.8, < 11.1.10-h30
>= 11.1.11, < 11.1.13-h9
>= 11.1.14, < 11.1.16
11.1.4-h35
11.1.6-h35
11.1.7-h8
11.1.10-h30
11.1.13-h9
11.1.16
10.2
>= 10.2.0, < 10.2.7-h36
>= 10.2.8, < 10.2.10-h39
>= 10.2.11, < 10.2.13-h23
>= 10.2.14, < 10.2.16-h9
>= 10.2.17, < 10.2.18-h8
10.2.7-h36
10.2.10-h39
10.2.13-h23
10.2.16-h9
10.2.18-h8

Selon l’éditeur, les versions non listées ne sont pas affectées.

Produits concernés

  • Palo Alto Networks Cloud NGFW · All
  • Palo Alto Networks Prisma Access · 11.2.0 < 11.2.7-h18, 10.2.0 < 10.2.10-h39

Contournement / Remédiation de l’éditeur

Contournement · PAN-OS

No known workarounds exist for this issue.

Remédiation de l’éditeur · PAN-OS

VersionMinor Version RangeSuggested SolutionCloud NGFW Customers who prefer to upgrade can work with Palo Alto Networks support to schedule an on-demand software upgrade.PAN-OS 12.112.1.5 through 12.1.7-h*Upgrade to 12.1.7-h2 or 12.1.8 or later. 12.1.2 through 12.1.4-h*Upgrade to 12.1.4-h8 or 12.1.8 or later.PAN-OS 11.211.2.11 through 11.2.12Upgrade to 11.2.13 or later. 11.2.8 through 11.2.10-h*Upgrade to 11.2.10-h12 or 11.2.13 or later. 11.2.5 through 11.2.7-h*Upgrade to 11.2.7-h18 or 11.2.13 or later. 11.2.0 through 11.2.4-h*Upgrade to 11.2.4-h20 or 11.2.13 or later.PAN-OS 11.111.1.14 through 11.1.15Upgrade to 11.1.16 or later. 11.1.11 through 11.1.13-h*Upgrade to 11.1.13-h9 or 11.1.16 or later. 11.1.8 through 11.1.10-h*Upgrade to 11.1.10-h30 or 11.1.16 or later. 11.1.7 through 11.1.7-h*Upgrade to 11.1.7-h8 or 11.1.16 or later. 11.1.5 through 11.1.6-h*Upgrade to 11.1.6-h35 or 11.1.16 …

Références

Provenance

Chaque information de cette page provient des sources ci-dessous. Rien n’est rédigé par une IA.

Palo Alto Networks (CVE record)
Palo Alto Networks (CVE record) · 27 sept. 2026, 23:46 UTC · Analyseur patcharo-cve5/1.1.0
NVD
NVD · 27 sept. 2026, 23:44 UTC · Analyseur patcharo-nvd/1.0.0
FIRST EPSS
FIRST EPSS · 27 sept. 2026, 23:46 UTC · Analyseur patcharo-epss/1.0.0

Dernière vérification : 28 sept. 2026, 02:31 UTC