CVE-2024-3382: Palo Alto Networks PAN-OS
High severity, CVSS 7.5. EPSS: 0.9% chance of exploitation in the next 30 days.
A memory leak exists in Palo Alto Networks PAN-OS software that enables an attacker to send a burst of crafted packets through the firewall that eventually prevents the firewall from processing traffic. This issue applies only to PA-5400 Series devices that are running PAN-OS software with the SSL Forward Proxy feature enabled.
Affected products
- Palo Alto Networks PAN-OS: from 10.2.0, before 10.2.7 (fixed in 10.2.7); from 11.0.0, before 11.0.4 (fixed in 11.0.4); from 11.1.0, before 11.1.2 (fixed in 11.1.2); version 10.2.7 only
Published 2024-04-10. Last modified 2026-06-17.