peter bassill · operator
$ cve CVE-2024-3393 JSON

CVE-2024-3393 KEV

7.5
HIGH · CVSS 3.1 · EPSS 28.4% (pctl 98)

Patch first

On CISA KEV — known exploited in the wild, due 2025-01-20.

Description

A Denial of Service vulnerability in the DNS Security feature of Palo Alto Networks PAN-OS software allows an unauthenticated attacker to send a malicious packet through the data plane of the firewall that reboots the firewall. Repeated attempts to trigger this condition will cause the firewall to enter maintenance mode.

Scoring

CVSS7.5 (HIGH, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS28.41% — more likely to be exploited than 98% of all CVEs
WeaknessCWE-754
On CISA KEVyes — remediate by 2025-01-20
Public exploitnone known
Published2024-12-27
Last modified2026-06-17

CISA KEV

NamePalo Alto Networks PAN-OS Malicious DNS Packet Vulnerability
Added2024-12-30
Due2025-01-20
Vendor / productPalo Alto Networks / PAN-OS
Ransomware usenone reported

Affected (2)

VendorProduct
paloaltonetworkspan-os
paloaltonetworksprisma access

References

→ the Explorer  ·  watch your stack  ·  NVD