انتقل إلى المحتوى الرئيسي
English
logo
مستوى الخطورة: عالية
ثغرة

الرقم المرجعي: NCSC-TAD-2412-001CVSS 0

DoS Vulnerability in Palo Alto Network PAN-OS

نوع التهديد:
غير متوفر
مستوى المشاركة (TLP):
CLEAR
CVE:
CVE-2024-3393

نظرة عامة

Palo Alto Networks has released a security patch to address a high-severity vulnerability (CVE-2024-3393) affecting PAN-OS’s DNS Security feature causing Denial of Service (DoS) attacks.

The vulnerability could be exploited by sending specific crafted DNS packets through the firewall, causing unexpected reboot. If the attack is repeated, the firewall may enter maintenance mode, requiring manual intervention to restore functionality. Successful exploitation could lead to disrupted connectivity and delayed response times. Systems are vulnerable if they have an active DNS Security License (or Advanced DNS Security License) applied and the DNS Security Logging feature enabled.

التقنيات المتأثرة

  • PAN-OS 11.2 < 11.2.3*
  • PAN-OS 11.1 < 11.1.5*
  • PAN-OS 10.2 >= 10.2.8*, <10.2.14*
  • PAN-OS 10.1 >= 10.1.14*, <10.1.15*
  • Prisma Access >= 10.2.8* on PAN-OS, <11.2.3* on PAN-OS

إجراءات الحد من المخاطر والإجراءات الفورية

  1. 01

    Update all affected systems to the latest fixed versions immediately.

  2. 02

    For more specific patch details refer to the official Palo Alto Networks advisory through this link: https://securityadvisories.paloaltonetworks.com/CVE-2024-3393

المراجع