CVE-2024-3385: PAN-OS: Firewall Denial of Service (DoS) when GTP Security is Disabled
A packet processing mechanism in Palo Alto Networks PAN-OS software enables a remote attacker to reboot hardware-based firewalls. Repeated attacks eventually cause the firewall to enter maintenance mode, which requires manual intervention to bring the firewall back online.
This affects the following hardware firewall models: - PA-5400 Series firewalls - PA-7000 Series firewalls
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-3385?
CVE-2024-3385 is classified as a critical severity vulnerability in Palo Alto Networks PAN-OS.
How does CVE-2024-3385 affect my firewall?
CVE-2024-3385 allows a remote attacker to reboot hardware-based firewalls, leading to maintenance mode and requiring manual intervention to recover.
How do I fix CVE-2024-3385?
To fix CVE-2024-3385, you should update Palo Alto Networks PAN-OS to the latest patched version recommended by the vendor.
Who is affected by CVE-2024-3385?
CVE-2024-3385 affects various versions of Palo Alto Networks PAN-OS, specifically versions 9.0, 9.1, 10.1, 10.2, and 11.0.
What should I do if I cannot immediately update for CVE-2024-3385?
If immediate updating for CVE-2024-3385 is not possible, consider implementing additional security measures, such as network segmentation and monitoring for suspicious activity.