CVE-2024-3393
A Denial of Service vulnerability in the DNS Security feature of Palo Alto Networks PAN-OS software allows an unauthenticated attacker to send a malicious packet through the data plane of the firewall that reboots the firewall. Repeated attempts to trigger this condition will cause the firewall to enter maintenance mode.
- Affected products
- Pan-Os, Prisma Access
- Paloaltonetworks Pan-os
- β€ 11.1.1, 11.2.3, 10.1.14, 10.2.8, 10.2.9, 10.2.10, 10.2.11, 10.2.12, 10.2.13, 11.1.2, 11.1.3, 11.1.4
- Fix
- Available
- CVSS 4.0
- 8.7 HIGH
- CVSS 3.1
- 7.5 HIGH
- EPSS
- 26.6% (98th percentile)
- Weakness
- CWE-754
- NVD status
- Analyzed
- Published
- 2024-12-27
- Attack patterns
- CAPEC-540
Workaround
If your firewall running the vulnerable PAN-OS versions stops responding or reboots unexpectedly and you cannot immediately apply a fix, apply a workaround below based on your deployment. Unmanaged NGFWs, NGFW managed by Panorama, or Prisma Access managed by Panorama * For each Anti-spyware profile, navigate to Objects β Security Profiles β Anti-spyware β (select a profile) β DNS Policies β DNS Security. * Change the Log Severity to "none" for all configured DNS Security categories. * Commit the changes. Remember to revert the Log Severity settings once the fixes are applied. NGFW managed by Strata Cloud Manager (SCM) You can choose one of the following mitigation options: * Option 1: Disable DNS Security logging directly on each NGFW by following the PAN-OS steps above. * Option 2: Disable DNS Security logging across all NGFWs in your tenant by opening a support case https://support.paloaltonetworks.com/Support/Index . Prisma Access managed by Strata Cloud Manager (SCM) Until we perform an upgrade of your Prisma Access tenant, you can disable DNS Security logging across all NGFWs in your tenant by opening a support case https://support.paloaltonetworks.com/Support/Index . If youβ¦
No indexed exploits for CVE-2024-3393 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2024-3393 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows β not that no exploit exists.