CVE-2024-3393highunder attackCWE-754

CVE-2024-3393: high-severity vulnerability in Palo Alto Networks PAN-OS

PAN-OS: Firewall Denial of Service (DoS) in DNS Security Using a Specially Crafted Packet

Published · Updated

76Vexday Risk Score

Prioritize patching. It under exploitation confirmed by CISA and has a public proof of concept.

ssvc Actcvss 8.7epss 29%
from disclosure to weapon13 days
Published on NVDDec 27
1st PoC+13d
CISA KEV+3d
exploitation probability
29%top 2% of all CVEs
observed exploitation
yesCISA + VulnCheck
1 public exploit(s)
Action required by CISAfederal deadline: 2025-01-20

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

In short

A flaw in Palo Alto Networks PAN-OS DNS Security feature allows an attacker to crash the firewall by sending a specially crafted packet, causing it to reboot repeatedly until it stops working.

Technical detail

An unauthenticated attacker can exploit a denial of service vulnerability in the PAN-OS DNS Security feature by sending a malicious packet through the firewall's data plane, triggering an uncontrolled reboot condition. Repeated exploitation forces the device into maintenance mode, rendering it unavailable.

Summary generated and translated by AI from the official description.

The full analysis of this CVE is available in Portuguese →

A Denial of Service vulnerability in the DNS Security feature of Palo Alto Networks PAN-OS software allows an unauthenticated attacker to send a malicious packet through the data plane of the firewall that reboots the firewall. Repeated attempts to trigger this condition will cause the firewall to enter maintenance mode.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L/AU:N/R:U/V:C/RE:M/U:Amber
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.