
- Home
- Threat Advisories
- NCSC-TAD-2412-001
NCSC-TAD-2412-001
Reference No.: NCSC-TAD-2412-001CVSS 0
DoS Vulnerability in Palo Alto Network PAN-OS
- Threat Type:
- N/A
- TLP:
- CLEAR
- CVE:
- CVE-2024-3393
Overview
Palo Alto Networks has released a security patch to address a high-severity vulnerability (CVE-2024-3393) affecting PAN-OS’s DNS Security feature causing Denial of Service (DoS) attacks.
The vulnerability could be exploited by sending specific crafted DNS packets through the firewall, causing unexpected reboot. If the attack is repeated, the firewall may enter maintenance mode, requiring manual intervention to restore functionality. Successful exploitation could lead to disrupted connectivity and delayed response times. Systems are vulnerable if they have an active DNS Security License (or Advanced DNS Security License) applied and the DNS Security Logging feature enabled.
Affected Technologies
- PAN-OS 11.2 < 11.2.3*
- PAN-OS 11.1 < 11.1.5*
- PAN-OS 10.2 >= 10.2.8*, <10.2.14*
- PAN-OS 10.1 >= 10.1.14*, <10.1.15*
- Prisma Access >= 10.2.8* on PAN-OS, <11.2.3* on PAN-OS
Mitigation and Immediate Actions
- 01
Update all affected systems to the latest fixed versions immediately.
- 02
For more specific patch details refer to the official Palo Alto Networks advisory through this link: https://securityadvisories.paloaltonetworks.com/CVE-2024-3393

