EXPOSURES › CVE-2024-3393
CVE-2024-3393
HIGH ⌖ ON CISA KEV · EXPLOITEDPalo Alto Networks PAN-OS allows unauthenticated remote reboots via malicious DNS packet parsing flaws.
An unauthenticated attacker can remotely reboot a Palo Alto PAN-OS firewall by exploiting a DNS Security parsing vulnerability, forcing the device into maintenance mode. This poses a critical risk to DIB organizations relying on Palo Alto firewalls for network segmentation and compliance controls, as it bypasses authentication entirely and disrupts security boundaries.
Shame score — The vulnerability allows unauthenticated remote reboots, a severe denial-of-service and operational disruption that undermines the trust in Palo Alto's core security product.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Palo Alto Networks PAN-OS contains a vulnerability in parsing and logging malicious DNS packets in the DNS Security feature that, when exploited, allows an unauthenticated attacker to remotely reboot the firewall. Repeated attempts to trigger this condition will cause the firewall to enter maintenance mode.
| PRODUCT | STATUS |
|---|---|
| GCS-HIGH Palo Alto Networks, Inc. |
Ready |
| Palo Alto Networks Government Cloud Services Palo Alto Networks, Inc. |
Authorized |