← Back to CVE List
Vulnerability Intelligence Report
PAN-OS: Firewall Denial of Service (DoS) in DNS Security Using a Specially Crafted Packet

CVE-2024-3393

A Denial of Service vulnerability in the DNS Security feature of Palo Alto Networks PAN-OS software allows an unauthenticated attacker to send a malicious packet through the data plane of the firewall that reboots the firewall. Repeated attempts to trigger this condition will cause the firewall to enter maintenance mode.

CISA KEV SSVC: Active Exploitation Automatable
CVSS Base Score
8.7
HIGH
EPSS Probability:26.64%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
Authentication
Weaponization
SSVC Action

Weaknesses (CWE)

CWE-754 ↗CWE-754 Improper Check for Unusual or Exceptional Conditions

Affected Products & Versions

Vendor Product Affected Versions
Palo Alto Networks Cloud NGFW All (unaffected)
Palo Alto Networks PAN-OS 11.2.0 < 11.2.3 (affected), 11.1.0 < 11.1.2-h16 (affected), 10.2.8 < 10.2.8-h19 (affected), 10.1.14 < 10.1.14-h8 (affected)
Palo Alto Networks PAN-OS 10.2.0 < 10.2.8 (unaffected), 11.2.0 < 11.2.3 (affected)

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

CISA KEV
ACTIVE IN CATALOG
EPSS Score
26.636%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityPalo Alto Networks, Inc. · Vendor · USA
Reserved2024-04-05T17:40:24
Published2024-12-27T09:44:24
Patch Date2024-12-27
Last Updated2025-10-21T22:55:33

LINK COPIED TO CLIPBOARD