CVE-2024-3393: PAN-OS: Firewall Denial of Service (DoS) in DNS Security Using a Specially Crafted Packet
A Denial of Service vulnerability in the DNS Security feature of Palo Alto Networks PAN-OS software allows an unauthenticated attacker to send a malicious packet through the data plane of the firewall that reboots the firewall. Repeated attempts to trigger this condition will cause the firewall to enter maintenance mode.
Other sources
Palo Alto Networks PAN-OS contains a vulnerability in parsing and logging malicious DNS packets in the DNS Security feature that, when exploited, allows an unauthenticated attacker to remotely reboot the firewall. Repeated attempts to trigger this condition will cause the firewall to enter maintenance mode.
— CISA
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Palo Alto PAN-OSto a version that resolves this vulnerability.Fixed in 11.2.3Fixed in 11.1.5Fixed in 11.1.4-h7Fixed in 11.1.2-h16Fixed in 11.1.3-h13 - Upgrade
Upgrade
Palo Alto Networks PAN-OSto a version that resolves this vulnerability.Fixed in 10.1.14-h8 - Upgrade
Upgrade
Palo Alto Networks PAN-OSto a version that resolves this vulnerability.Fixed in 10.1.15 - Upgrade
Upgrade
Palo Alto Networks PAN-OSto a version that resolves this vulnerability.Fixed in 10.2.8-h19 - Upgrade
Upgrade
Palo Alto Networks PAN-OSto a version that resolves this vulnerability.Fixed in 10.2.9-h19 - Upgrade
Upgrade
Palo Alto Networks PAN-OSto a version that resolves this vulnerability.Fixed in 10.2.10-h12 - Upgrade
Upgrade
Palo Alto Networks PAN-OSto a version that resolves this vulnerability.Fixed in 10.2.11-h10 - Upgrade
Upgrade
Palo Alto Networks PAN-OSto a version that resolves this vulnerability.Fixed in 10.2.12-h4 - Upgrade
Upgrade
Palo Alto Networks PAN-OSto a version that resolves this vulnerability.Fixed in 10.2.13-h2 - Upgrade
Upgrade
Palo Alto Networks PAN-OSto a version that resolves this vulnerability.Fixed in 10.2.14 - Upgrade
Upgrade
Palo Alto Networks PAN-OSto a version that resolves this vulnerability.Fixed in 11.1.2-h16 - Upgrade
Upgrade
Palo Alto Networks PAN-OSto a version that resolves this vulnerability.Fixed in 11.1.3-h13 - Upgrade
Upgrade
Palo Alto Networks PAN-OSto a version that resolves this vulnerability.Fixed in 11.1.4-h7 - Upgrade
Upgrade
Palo Alto Networks PAN-OSto a version that resolves this vulnerability.Fixed in 11.1.5 - Upgrade
Upgrade
Palo Alto Networks PAN-OSto a version that resolves this vulnerability.Fixed in 11.2.3 - Configuration
For all configured DNS Security categories, set Log Severity to "none". If using predefined Anti-Spyware profiles, clone the relevant profile into a custom Anti-Spyware profile and replace the predefined profile or group in the applicable Security Rules. Revert the Log Severity settings after applying the PAN-OS fix.
PAN-OS DNS Security Log Severity = none
Event History
Frequently Asked Questions
What is the severity of CVE-2024-3393?
CVE-2024-3393 has a high severity because it allows an unauthenticated attacker to remotely reboot the affected firewall due to a Denial of Service vulnerability.
How do I fix CVE-2024-3393?
To fix CVE-2024-3393, you should upgrade your Palo Alto Networks PAN-OS to a version that addresses this vulnerability, specifically versions 11.2.3, 11.1.5, 11.1.4-h6, 11.1.2-h16, or 11.1.3-h13.
What types of Palo Alto Networks products are affected by CVE-2024-3393?
CVE-2024-3393 affects the Palo Alto Networks PAN-OS and Cloud NGFW products.
What happens if CVE-2024-3393 is exploited?
If exploited, CVE-2024-3393 allows attackers to send a malicious packet that causes the affected firewall to reboot, resulting in a Denial of Service.
Is there a work-around for CVE-2024-3393?
Currently, there is no known work-around for CVE-2024-3393, so upgrading the affected software is the recommended action.