CVE-2024-3393
KEVlarge1Unauthenticated Remote DoS via DNS Packet Parsing in Palo Alto Networks PAN-OS
CISA: Palo Alto Networks PAN-OS Malicious DNS Packet Vulnerability
Palo Alto Networks PAN-OS contains a flaw (CWE-754) in how the DNS Security feature parses and logs malicious DNS packets, which an unauthenticated remote attacker can abuse by sending crafted DNS traffic to a firewall with the feature enabled. Successful exploitation triggers a remote reboot of the firewall, and repeated exploitation attempts can push the device into maintenance mode, causing a sustained denial of service until an administrator intervenes. Only PAN-OS deployments that use the DNS Security feature are affected; the attacker requires no credentials, only network reachability to traffic inspected by the firewall. The flaw was added to the CISA KEV catalog on 2024-12-30, indicating confirmed in-the-wild exploitation, and its EPSS score of 28.4% (98th percentile) signals elevated exploitation risk, though no public proof-of-concept code is known and CVSS scoring is not yet available.
What to do: Check the Palo Alto Networks advisory for this CVE to determine whether your PAN-OS release with DNS Security enabled is affected, and upgrade to the recommended fixed hotfix release per vendor instructions; if mitigations are unavailable, CISA's KEV guidance is to discontinue use of the affected product. Limit exposure of firewall interfaces and DNS Security processing paths to untrusted DNS traffic, and monitor devices for unexplained reboots or entry into maintenance mode, which would indicate exploitation attempts.
| Palo Alto Networks PAN-OS | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A Denial of Service vulnerability in the DNS Security feature of Palo Alto Networks PAN-OS software allows an unauthenticated attacker to send a malicious packet through the data plane of the firewall that reboots the firewall. Repeated attempts to trigger this condition will cause the firewall to enter maintenance mode.
- Affected
- Palo Alto Networks PAN-OS
- Required action
- Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
- Due date
- Ransomware use
- Unknown
- Vendors
- paloaltonetworks
- Products
- pan-os, prisma access
- Weakness
- CWE-754
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:C/RE:M/U:Amber