Palo Alto Networks fixed a high-severity PAN
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2024-3393 | Unauthenticated Remote DoS via DNS Packet Parsing in Palo Alto Networks PAN-OS Palo Alto Networks PAN-OS contains a flaw (CWE-754) in how the DNS Security feature parses and logs malicious DNS packets, which an unauthenticated remote attacker can abuse by sending crafted DNS traffic to a firewall with the feature enabled. Successful exploitation triggers a remote reboot of the firewall, and repeated exploitation attempts can push the device into maintenance mode, causing a sustained denial of service until an administrator intervenes. Only PAN-OS deployments that use the DNS Security feature are affected; the attacker requires no credentials, only network reachability to traffic inspected by the firewall. The flaw was added to the CISA KEV catalog on 2024-12-30, indicating confirmed in-the-wild exploitation, and its EPSS score of 28.4% (98th percentile) signals elevated exploitation risk, though no public proof-of-concept code is known and CVSS scoring is not yet available. Do: Check the Palo Alto Networks advisory for this CVE to determine whether your PAN-OS release with DNS Security enabled is affected, and upgrade to the recommended fixed hotfix release per vendor instructions; if mitigations are unavailable, CISA's KEV guidance is to discontinue use of the affected product. Limit exposure of firewall interfaces and DNS Security processing paths to untrusted DNS traffic, and monitor devices for unexplained reboots or entry into maintenance mode, which would indicate exploitation attempts. | 8.7 | 28% | KEV |
| largetens of thousands of PAN-OS firewalls plausibly affected (roughly 10k-100k systems, limited to devices with DNS Security enabled) |
Full article350 words · extracted from securityaffairs.com · click to collapse
Pierluigi Paganini
December 27, 2024

Palo Alto Networks addressed a high-severity PAN-OS flaw that could trigger denial-of-service (DoS) on vulnerable devices.
Palo Alto Networks addressed a high-severity flaw, tracked as CVE-2024-3393 (CVSS score: 8.7), in PAN-OS software that could cause a denial-of-service (DoS) condition.
An unauthenticated attacker can exploit this vulnerability to reboot the firewall by sending a malicious packet through its data plane. Repeated exploitation forces the firewall into maintenance mode.
“A Denial of Service vulnerability in the DNS Security feature of Palo Alto Networks PAN-OS software allows an unauthenticated attacker to send a malicious packet through the data plane of the firewall that reboots the firewall. Repeated attempts to trigger this condition will cause the firewall to enter maintenance mode.” reads the advisory.
The flaw’s severity is reduced to a CVSS score of 7.1 when access is limited to authenticated end users via Prisma Access.
The vulnerability affects PAN-OS versions 10.X and 11.X, including Prisma Access running these versions. It is fixed in PAN-OS 10.1.14-h8, 10.2.10-h12, 11.1.5, 11.2.3, and all later versions.
The vulnerability can be exploited only if DNS Security logging is enabled.
Palo Alto Networks is aware of customers facing denial of service (DoS) conditions when their firewall blocks malicious DNS packets, which trigger this issue.
The cybersecurity vendor addressed the issue with the releases PAN-OS 10.1.14-h8, PAN-OS 10.2.10-h12, PAN-OS 11.1.5, PAN-OS 11.2.3, and all later PAN-OS versions.
The company noted that PAN-OS 11.0 reached the end of life (EOL) on November 17, 2024, for this reason, it will not provide a fix for this release.
To mitigate the issue, customers can set Log Severity to “none” for all DNS Security categories in each Anti-Spyware profile via the DNS Policies settings in Panorama or unmanaged firewalls.
For firewalls managed by Strata Cloud Manager (SCM), users can disable DNS Security logging on each device or across all devices by opening a support case. Prisma Access tenants should also open a support case to disable logging until an upgrade is completed.
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, PAN-OS)
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/172370/security/palo-alto-networks-high-severity-pan-os-flaw.html