Home / Vulnerabilities / CVE-2024-3393
HIGH SEVERITY
CVE-2024-3393 Palo Alto Networks · PAN-OS

Palo Alto Networks PAN-OS Malicious DNS Packet Vulnerability

Technical Severity

CVSS v3.1 Metrics

HIGH
7.5 / 10
Minimal Risk Critical
Vector Specification
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Exploitation Likelihood

EPSS Prediction

78.02 %
Predictive Probability
Percentile Rank
99.0 th

Documented as more likely to be exploited than 99.0% of known CVEs.

Detection Date

Dec 30, 2024

Remediation Due

Jan 20, 2025

CISA Catalog Active

Threat Analysis

Palo Alto Networks PAN-OS contains a vulnerability in parsing and logging malicious DNS packets in the DNS Security feature that, when exploited, allows an unauthenticated attacker to remotely reboot the firewall. Repeated attempts to trigger this condition will cause the firewall to enter maintenance mode.

Remediation Directive

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

External Intelligence