Site icon TheCyberThrone

CVE-2024-3393 DoS Vulnerability in Palo Alto PAN-OS

Advertisements

CVE-2024-3393 is a high-severity Denial of Service (DoS) vulnerability discovered in the DNS Security feature of Palo Alto Networks’ PAN-OS software. This vulnerability can be exploited by an unauthenticated attacker, meaning the attacker does not need any credentials or special permissions to execute the attack.

Key Details:

How It Works:

An attacker can exploit this vulnerability by sending a specially crafted malicious packet through the firewall’s data plane. The data plane is responsible for processing network traffic and enforcing security policies. When the firewall receives this malicious packet, it causes the device to reboot unexpectedly. Repeated exploitation of this vulnerability can force the firewall into a maintenance mode, significantly impacting the availability of network services.

Advertisements

Impact:

Mitigation:

Palo Alto Networks has released patches to address this vulnerability in the following versions:

Organizations using affected versions of PAN-OS are strongly urged to apply these patches as soon as possible to mitigate the risk. If immediate patching is not feasible, disabling DNS Security logging is recommended as a temporary workaround to reduce the potential impact of this vulnerability.

Exit mobile version