CVE-2021-3053: PAN-OS: Exceptional Condition Denial-of-Service (DoS)
An improper handling of exceptional conditions vulnerability exists in the Palo Alto Networks PAN-OS dataplane that enables an unauthenticated network-based attacker to send specifically crafted traffic through the firewall that causes the service to crash. Repeated attempts to send this request result in denial of service to all PAN-OS services by restarting the device and putting it into maintenance mode. This issue impacts: PAN-OS 8.1 versions earlier than PAN-OS 8.1.20; PAN-OS 9.0 versions earlier than PAN-OS 9.0.14; PAN-OS 9.1 versions earlier than PAN-OS 9.1.9; PAN-OS 10.0 versions earlier than PAN-OS 10.0.5. This issue does not affect Prisma Access.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Palo Alto Networks PAN-OS dataplaneto a version that resolves this vulnerability.Fixed in 8.1.20 - Upgrade
Upgrade
Palo Alto Networks PAN-OS dataplaneto a version that resolves this vulnerability.Fixed in 9.0.14 - Upgrade
Upgrade
Palo Alto Networks PAN-OS dataplaneto a version that resolves this vulnerability.Fixed in 9.1.9 - Upgrade
Upgrade
Palo Alto Networks PAN-OS dataplaneto a version that resolves this vulnerability.Fixed in 10.0.5
Event History
Frequently Asked Questions
What is CVE-2021-3053?
CVE-2021-3053 is an improper handling of exceptional conditions vulnerability in the Palo Alto Networks PAN-OS dataplane.
How does CVE-2021-3053 affect Palo Alto Networks PAN-OS?
CVE-2021-3053 affects Palo Alto Networks PAN-OS versions 8.1.0 to 8.1.20, 9.0.0 to 9.0.14, 9.1.0 to 9.1.9, and 10.0.0 to 10.0.5.
How severe is CVE-2021-3053?
CVE-2021-3053 has a severity rating of 7.5 (High).
How can an attacker exploit CVE-2021-3053?
An unauthenticated network-based attacker can exploit CVE-2021-3053 by sending specifically crafted traffic through the firewall, causing the service to crash.
Is there a fix available for CVE-2021-3053?
Yes, Palo Alto Networks has released security updates to address CVE-2021-3053.