SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityAnalyzed

CVE-2024-3393

Palo Alto Networks PAN-OS Malicious DNS Packet Vulnerability

KEVHIGH 8.7EPSS 28.4%

Does this matter?

Known to be exploited in the wild (CISA KEV, CISA remediation deadline 20 January 2025). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.

Description

A Denial of Service vulnerability in the DNS Security feature of Palo Alto Networks PAN-OS software allows an unauthenticated attacker to send a malicious packet through the data plane of the firewall that reboots the firewall. Repeated attempts to trigger this condition will cause the firewall to enter maintenance mode.

CVSS 4.0
8.7 HIGHCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/M
EPSS
28.41% probability · 98th percentile
CISA KEV
Listed 30 December 2024 · due 20 January 2025
Weakness
CWE-754
Affected
paloaltonetworks/pan-os · paloaltonetworks/prisma access
Source
psirt@paloaltonetworks.com

CISA notes

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. https://security.paloaltonetworks.com/CVE-2024-3393 ; https://nvd.nist.gov/vuln/detail/CVE-2024-3393

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.