CVE-2024-3393

CVE Published 2024-12-27
Related CWE(s) CWE-754: Improper Check for Unusual or Exceptional Conditions
Related Vendor(s) paloaltonetworks
Related Product(s) pan-os, prisma_access
Exploitation Reported (CISA KEV) 2024-12-30
CVSS 3 Base Score 7.5 (HIGH)
CVSS 3 Attack Complexity LOW
CVSS 3 Attack Vector NETWORK

A Denial of Service vulnerability in the DNS Security feature of Palo Alto Networks PAN-OS software allows an unauthenticated attacker to send a malicious packet through the data plane of the firewall that reboots the firewall. Repeated attempts to trigger this condition will cause the firewall to enter maintenance mode.

Cyber Threat Graph Context

Explore how this CVE relates to the wider threat graph

References