Skip to content
COOEY

EXPOSURES › CVE-2024-3393

CVE-2024-3393

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2024-12-30 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2024-3393 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 85/100 exploited-in-wildunpatchedransomware

Palo Alto Networks PAN-OS allows unauthenticated remote reboots via malicious DNS packet parsing flaws.

An unauthenticated attacker can remotely reboot a Palo Alto PAN-OS firewall by exploiting a DNS Security parsing vulnerability, forcing the device into maintenance mode. This poses a critical risk to DIB organizations relying on Palo Alto firewalls for network segmentation and compliance controls, as it bypasses authentication entirely and disrupts security boundaries.

Shame score — The vulnerability allows unauthenticated remote reboots, a severe denial-of-service and operational disruption that undermines the trust in Palo Alto's core security product.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Palo Alto Networks PAN-OS contains a vulnerability in parsing and logging malicious DNS packets in the DNS Security feature that, when exploited, allows an unauthenticated attacker to remotely reboot the firewall. Repeated attempts to trigger this condition will cause the firewall to enter maintenance mode.

AFFECTED FEDRAMP PRODUCTS · 2
PRODUCTSTATUS
GCS-HIGH
Palo Alto Networks, Inc.
Ready
Palo Alto Networks Government Cloud Services
Palo Alto Networks, Inc.
Authorized