CVE-2024-3393: high-severity vulnerability in Palo Alto Networks PAN-OS
PAN-OS: Firewall Denial of Service (DoS) in DNS Security Using a Specially Crafted Packet
Published · Updated
Prioritize patching. It under exploitation confirmed by CISA and has a public proof of concept.
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
A flaw in Palo Alto Networks PAN-OS DNS Security feature allows an attacker to crash the firewall by sending a specially crafted packet, causing it to reboot repeatedly until it stops working.
An unauthenticated attacker can exploit a denial of service vulnerability in the PAN-OS DNS Security feature by sending a malicious packet through the firewall's data plane, triggering an uncontrolled reboot condition. Repeated exploitation forces the device into maintenance mode, rendering it unavailable.
The full analysis of this CVE is available in Portuguese →
In the same product, most dangerous first.