CVE-2024-3387: PAN-OS: Weak Certificate Strength in Panorama Software Leads to Sensitive Information Disclosure
A weak (low bit strength) device certificate in Palo Alto Networks Panorama software enables an attacker to perform a meddler-in-the-middle (MitM) attack to capture encrypted traffic between the Panorama management server and the firewalls it manages. With sufficient computing resources, the attacker could break encrypted communication and expose sensitive information that is shared between the management server and the firewalls.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-3387?
CVE-2024-3387 is classified as a high-severity vulnerability due to its potential to facilitate MitM attacks.
How do I fix CVE-2024-3387?
To mitigate CVE-2024-3387, you should update to the latest version of Palo Alto Networks Panorama that addresses this vulnerability.
What types of attacks can be executed by exploiting CVE-2024-3387?
Exploiting CVE-2024-3387 can enable attackers to execute meddler-in-the-middle (MitM) attacks and capture encrypted traffic.
What are the risks of unpatched CVE-2024-3387?
Unpatched CVE-2024-3387 can lead to unauthorized access to sensitive data through intercepted communications between the Panorama server and managed firewalls.
Which software versions are affected by CVE-2024-3387?
CVE-2024-3387 affects all versions of Palo Alto Networks Panorama that utilize weak device certificates.