CVE-2024-3393: PAN-OS: Firewall Denial of Service (DoS) in DNS Security Using a Specially Crafted Packet
A Denial of Service vulnerability in the DNS Security feature of Palo Alto Networks PAN-OS software allows an unauthenticated attacker to send a malicious packet through the data plane of the firewall that reboots the firewall. Repeated attempts to trigger this condition will cause the firewall to enter maintenance mode.
Other sources
Palo Alto Networks PAN-OS contains a vulnerability in parsing and logging malicious DNS packets in the DNS Security feature that, when exploited, allows an unauthenticated attacker to remotely reboot the firewall. Repeated attempts to trigger this condition will cause the firewall to enter maintenance mode.
— CISA
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Palo Alto PAN-OSto a version that resolves this vulnerability.Fixed in 11.2.3Fixed in 11.1.5Fixed in 11.1.4-h7Fixed in 11.1.2-h16Fixed in 11.1.3-h13 - Upgrade
Upgrade
Palo Alto PAN-OSto a version that resolves this vulnerability.Fixed in 10.1.14-h8 - Upgrade
Upgrade
Palo Alto PAN-OSto a version that resolves this vulnerability.Fixed in 10.1.15 - Upgrade
Upgrade
Palo Alto PAN-OSto a version that resolves this vulnerability.Fixed in 10.2.10-h12 - Upgrade
Upgrade
Palo Alto PAN-OSto a version that resolves this vulnerability.Fixed in 10.2.11-h10 - Upgrade
Upgrade
Palo Alto PAN-OSto a version that resolves this vulnerability.Fixed in 10.2.12-h4 - Upgrade
Upgrade
Palo Alto PAN-OSto a version that resolves this vulnerability.Fixed in 10.2.13-h2 - Upgrade
Upgrade
Palo Alto PAN-OSto a version that resolves this vulnerability.Fixed in 10.2.14 - Upgrade
Upgrade
Palo Alto PAN-OSto a version that resolves this vulnerability.Fixed in 10.2.8-h19 - Upgrade
Upgrade
Palo Alto PAN-OSto a version that resolves this vulnerability.Fixed in 10.2.9-h19 - Upgrade
Upgrade
Palo Alto PAN-OSto a version that resolves this vulnerability.Fixed in 11.1.2-h16 - Upgrade
Upgrade
Palo Alto PAN-OSto a version that resolves this vulnerability.Fixed in 11.1.3-h13 - Upgrade
Upgrade
Palo Alto PAN-OSto a version that resolves this vulnerability.Fixed in 11.1.4-h7 - Upgrade
Upgrade
Palo Alto PAN-OSto a version that resolves this vulnerability.Fixed in 11.1.5 - Upgrade
Upgrade
Palo Alto PAN-OSto a version that resolves this vulnerability.Fixed in 11.2.3 - Configuration
For each custom Anti-Spyware profile: Objects → Security Profiles → Anti-Spyware → (select profile) → DNS Policies → DNS Security — change Log Severity to 'none' for all configured DNS Security categories; commit the changes.
Anti-Spyware -> DNS Security Log Severity = none - Configuration
If using predefined Anti-Spyware profiles (Default or Strict), clone each relevant predefined Anti-Spyware profile to create a custom profile, then replace the predefined profile in your Security Rules (Policies → Security → (security rule) → Actions → Profiles or Actions → Group) with the cloned custom Anti-Spyware profile or group.
Anti-Spyware profile profile usage in Security Rules = use cloned custom profile - Compensating control
Disable DNS Security logging across all NGFWs in your tenant by opening a support case with Palo Alto Networks to request tenant-wide disabling of DNS Security logging until fixes can be applied.
- Operational
Ensure that a DNS Security Configuration is present in the device configuration before changing Log Severity settings.
- Operational
Commit the configuration changes after adjusting Anti-Spyware/DNS Security settings.
- Operational
After applying the PAN-OS fixes (for example one of: 10.1.15, 10.2.14, 11.1.5, 11.2.3 or later), revert the Log Severity settings from 'none' back to their prior values.
Event History
Frequently Asked Questions
What is the severity of CVE-2024-3393?
CVE-2024-3393 has a high severity because it allows an unauthenticated attacker to remotely reboot the affected firewall due to a Denial of Service vulnerability.
How do I fix CVE-2024-3393?
To fix CVE-2024-3393, you should upgrade your Palo Alto Networks PAN-OS to a version that addresses this vulnerability, specifically versions 11.2.3, 11.1.5, 11.1.4-h6, 11.1.2-h16, or 11.1.3-h13.
What types of Palo Alto Networks products are affected by CVE-2024-3393?
CVE-2024-3393 affects the Palo Alto Networks PAN-OS and Cloud NGFW products.
What happens if CVE-2024-3393 is exploited?
If exploited, CVE-2024-3393 allows attackers to send a malicious packet that causes the affected firewall to reboot, resulting in a Denial of Service.
Is there a work-around for CVE-2024-3393?
Currently, there is no known work-around for CVE-2024-3393, so upgrading the affected software is the recommended action.