CVE-2024-3393: Palo Alto Networks PAN-OS Malicious DNS Packet Vulnerability
High severity, CVSS 7.5. Actively exploited: in CISA KEV since 2024-12-30. EPSS: 29.1% chance of exploitation in the next 30 days.
A Denial of Service vulnerability in the DNS Security feature of Palo Alto Networks PAN-OS software allows an unauthenticated attacker to send a malicious packet through the data plane of the firewall that reboots the firewall. Repeated attempts to trigger this condition will cause the firewall to enter maintenance mode.
Affected products
- Palo Alto Networks PAN-OS: from 11.1.0, up to and including 11.1.1; from 11.2.0, before 11.2.3 (fixed in 11.2.3); version 10.1.14 only; version 10.2.8 only; version 10.2.9 only; version 10.2.10 only; …
- Palo Alto Networks Prisma Access: affected versions not specified
Published 2024-12-27. Last modified 2026-06-17.