CVE-2024-3384: PAN-OS: Firewall Denial of Service (DoS) via Malformed NTLM Packets
A vulnerability in Palo Alto Networks PAN-OS software enables a remote attacker to reboot PAN-OS firewalls when receiving Windows New Technology LAN Manager (NTLM) packets from Windows servers. Repeated attacks eventually cause the firewall to enter maintenance mode, which requires manual intervention to bring the firewall back online.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-3384?
CVE-2024-3384 is classified as a high severity vulnerability due to its potential impact on the availability of PAN-OS firewalls.
How do I fix CVE-2024-3384?
To fix CVE-2024-3384, upgrade your PAN-OS to a version that is not affected, specifically versions 8.1.25, 9.0.18, 9.1.16, or 10.0.13 and later.
What systems are affected by CVE-2024-3384?
CVE-2024-3384 affects Palo Alto Networks PAN-OS versions 8.1.0 to 8.1.24, 9.0.0 to 9.0.17, 9.1.0 to 9.1.15, and 10.0.0 to 10.0.12.
What can attackers do with CVE-2024-3384?
Attackers can remotely reboot PAN-OS firewalls by sending malicious NTLM packets, causing disruption in network services.
Is there a workaround for CVE-2024-3384?
Currently, there are no documented workarounds for CVE-2024-3384 other than updating to a secure version.