CVE-2024-3383: Palo Alto Networks PAN-OS
Critical severity, CVSS 9.1. EPSS: 0.6% chance of exploitation in the next 30 days.
A vulnerability in how Palo Alto Networks PAN-OS software processes data received from Cloud Identity Engine (CIE) agents enables modification of User-ID groups. This impacts user access to network resources where users may be inappropriately denied or allowed access to resources based on your existing Security Policy rules.
Affected products
- Palo Alto Networks PAN-OS: from 10.1.0, before 10.1.11 (fixed in 10.1.11); from 10.2.0, before 10.2.5 (fixed in 10.2.5); from 11.0.0, before 11.0.3 (fixed in 11.0.3)
Published 2024-04-10. Last modified 2026-06-17.