Vulnerability Description
A Denial of Service vulnerability in the DNS Security feature of Palo Alto Networks PAN-OS software allows an unauthenticated attacker to send a malicious packet through the data plane of the firewall that reboots the firewall. Repeated attempts to trigger this condition will cause the firewall to enter maintenance mode.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Paloaltonetworks | Pan-Os | >= 11.1.0, <= 11.1.1 |
| Paloaltonetworks | Prisma Access | - |
Related Weaknesses (CWE)
References
- https://security.paloaltonetworks.com/CVE-2024-3393Vendor Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-US Government Resource
FAQ
What is CVE-2024-3393?
CVE-2024-3393 is a vulnerability with a CVSS score of 7.5 (HIGH). A Denial of Service vulnerability in the DNS Security feature of Palo Alto Networks PAN-OS software allows an unauthenticated attacker to send a malicious packet through the data plane of the firewall...
How severe is CVE-2024-3393?
CVE-2024-3393 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-3393?
Check the references section above for vendor advisories and patch information. Affected products include: Paloaltonetworks Pan-Os, Paloaltonetworks Prisma Access.