CVE-2024-2551: PAN-OS: Firewall Denial of Service (DoS) Using a Specially Crafted Packet (Severity: MEDIUM)
A null pointer dereference vulnerability in Palo Alto Networks PAN-OS software enables an unauthenticated attacker to stop a core system service on the firewall by sending a crafted packet through the data plane that causes a denial of service (DoS) condition. Repeated attempts to trigger this condition result in the firewall entering maintenance mode.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-2551?
CVE-2024-2551 is considered a critical vulnerability as it allows unauthenticated attackers to execute a denial of service (DoS) attack on the firewall.
How do I fix CVE-2024-2551?
To fix CVE-2024-2551, update your PAN-OS software to a version that is not affected, specifically version 11.0.5 or any patched version from the affected branches.
Which products are affected by CVE-2024-2551?
CVE-2024-2551 impacts Palo Alto Networks PAN-OS, Cloud NGFW, and Prisma Access, particularly those running specific vulnerable versions.
What type of attack is possible due to CVE-2024-2551?
CVE-2024-2551 enables a denial of service (DoS) condition by allowing attackers to stop core system services on affected firewalls.
Is user authentication required to exploit CVE-2024-2551?
No, user authentication is not required to exploit CVE-2024-2551, making it especially dangerous.