ZeroHour

CVE-2024-3393

KEVlarge1

Unauthenticated Remote DoS via DNS Packet Parsing in Palo Alto Networks PAN-OS

CISA: Palo Alto Networks PAN-OS Malicious DNS Packet Vulnerability

CVSS 4.0
8.7 high
EPSS
28%p98
Published
()
KEV added
AI analysis

Palo Alto Networks PAN-OS contains a flaw (CWE-754) in how the DNS Security feature parses and logs malicious DNS packets, which an unauthenticated remote attacker can abuse by sending crafted DNS traffic to a firewall with the feature enabled. Successful exploitation triggers a remote reboot of the firewall, and repeated exploitation attempts can push the device into maintenance mode, causing a sustained denial of service until an administrator intervenes. Only PAN-OS deployments that use the DNS Security feature are affected; the attacker requires no credentials, only network reachability to traffic inspected by the firewall. The flaw was added to the CISA KEV catalog on 2024-12-30, indicating confirmed in-the-wild exploitation, and its EPSS score of 28.4% (98th percentile) signals elevated exploitation risk, though no public proof-of-concept code is known and CVSS scoring is not yet available.

What to do: Check the Palo Alto Networks advisory for this CVE to determine whether your PAN-OS release with DNS Security enabled is affected, and upgrade to the recommended fixed hotfix release per vendor instructions; if mitigations are unavailable, CISA's KEV guidance is to discontinue use of the affected product. Limit exposure of firewall interfaces and DNS Security processing paths to untrusted DNS traffic, and monitor devices for unexplained reboots or entry into maintenance mode, which would indicate exploitation attempts.

Affected
Palo Alto Networks PAN-OS
Estimated exposure
largetens of thousands of PAN-OS firewalls plausibly affected (roughly 10k-100k systems, limited to devices with DNS Security enabled) — PAN-OS firewalls are widely deployed at enterprise and government network perimeters and public internet scans consistently show tens of thousands of exposed PAN-OS devices, though only the subset running the DNS Security…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A Denial of Service vulnerability in the DNS Security feature of Palo Alto Networks PAN-OS software allows an unauthenticated attacker to send a malicious packet through the data plane of the firewall that reboots the firewall. Repeated attempts to trigger this condition will cause the firewall to enter maintenance mode.

CISA Known Exploited Vulnerability
Affected
Palo Alto Networks PAN-OS
Required action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
paloaltonetworks
Products
pan-os, prisma access
Weakness
CWE-754
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:C/RE:M/U:Amber

In the news