CVE-2024-3385: Palo Alto Networks PAN-OS

High severity, CVSS 7.5. EPSS: 0.9% chance of exploitation in the next 30 days.

A packet processing mechanism in Palo Alto Networks PAN-OS software enables a remote attacker to reboot hardware-based firewalls. Repeated attacks eventually cause the firewall to enter maintenance mode, which requires manual intervention to bring the firewall back online. This affects the following hardware firewall models: - PA-5400 Series firewalls - PA-7000 Series firewalls

Affected products

  • Palo Alto Networks PAN-OS: from 9.0.0, up to and including 9.0.16; from 9.1.0, before 9.1.17 (fixed in 9.1.17); from 10.1.0, before 10.1.12 (fixed in 10.1.12); from 10.2.0, before 10.2.8 (fixed in 10.2.8); from 11.0.0, before 11.0.3 (fixed in 11.0.3); version 9.0.17 only

Published 2024-04-10. Last modified 2026-06-17.