CVE-2024-2550: PAN-OS: Firewall Denial of Service (DoS) in GlobalProtect Gateway Using a Specially Crafted Packet (Severity: MEDIUM)
A null pointer dereference vulnerability in the GlobalProtect gateway in Palo Alto Networks PAN-OS software enables an unauthenticated attacker to stop the GlobalProtect service on the firewall by sending a specially crafted packet that causes a denial of service (DoS) condition. Repeated attempts to trigger this condition result in the firewall entering maintenance mode.
Affected Software
Remediation
Information
Mitigation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-2550?
CVE-2024-2550 is classified as a denial-of-service vulnerability which can lead to significant service disruption.
How do I fix CVE-2024-2550?
To mitigate CVE-2024-2550, upgrade your Palo Alto Networks PAN-OS to versions 11.1.5, 11.0.6, 10.2.11 or apply the relevant security patches.
Which Palo Alto Networks products are affected by CVE-2024-2550?
CVE-2024-2550 impacts Palo Alto Networks PAN-OS, Prisma Access, and Cloud NGFW products.
What kind of attack vector does CVE-2024-2550 use?
CVE-2024-2550 can be exploited by an unauthenticated attacker sending a specially crafted packet to the GlobalProtect gateway.
What are the potential impacts of CVE-2024-2550?
Exploitation of CVE-2024-2550 can lead to a denial of service, causing the GlobalProtect service on the firewall to stop functioning.