CVE-2024-3382: PAN-OS: Firewall Denial of Service (DoS) via a Burst of Crafted Packets
A memory leak exists in Palo Alto Networks PAN-OS software that enables an attacker to send a burst of crafted packets through the firewall that eventually prevents the firewall from processing traffic. This issue applies only to PA-5400 Series devices that are running PAN-OS software with the SSL Forward Proxy feature enabled.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-3382?
CVE-2024-3382 is classified as a high severity vulnerability affecting Palo Alto Networks PAN-OS.
How do I fix CVE-2024-3382?
To fix CVE-2024-3382, upgrade your Palo Alto Networks PAN-OS to the latest patch or version provided by the vendor.
Which devices are affected by CVE-2024-3382?
CVE-2024-3382 affects PA-5400 Series devices running specific versions of PAN-OS from 10.2.0 to 10.2.7, 11.0.0 to 11.0.4, and 11.1.0 to 11.1.2.
What kind of attack does CVE-2024-3382 enable?
CVE-2024-3382 allows an attacker to exploit a memory leak by sending crafted packets through the firewall, which may lead to traffic processing failures.
Is there a workaround for CVE-2024-3382?
Currently, the recommended mitigation for CVE-2024-3382 is to apply the latest updates since no specific workaround has been documented.