CVE-2024-9472: PAN-OS: Firewall Denial of Service (DoS) Using Specially Crafted Traffic (Severity: MEDIUM)
A null pointer dereference in Palo Alto Networks PAN-OS software on PA-800 Series, PA-3200 Series, PA-5200 Series, and PA-7000 Series hardware platforms when Decryption policy is enabled allows an unauthenticated attacker to crash PAN-OS by sending specific traffic through the data plane, resulting in a denial of service (DoS) condition. Repeated attempts to trigger this condition will result in PAN-OS entering maintenance mode.
Palo Alto Networks VM-Series, Cloud NGFW, and Prisma Access are not affected.
This issue only affects PA-800 Series, PA-3200 Series, PA-5200 Series, and PA-7000 Series running these specific versions of PAN-OS:
10.2.7-h12 10.2.8-h10 10.2.9-h9 10.2.9-h11 10.2.10-h2 10.2.10-h3 10.2.11 10.2.11-h1 10.2.11-h2 10.2.11-h3 11.1.2-h9 11.1.2-h12 11.1.3-h2 11.1.3-h4 11.1.3-h6 11.2.2 11.2.2-h1
Affected Software
Remediation
Mitigation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-9472?
CVE-2024-9472 has been classified as a critical severity vulnerability due to the potential for denial of service.
How do I fix CVE-2024-9472?
To mitigate CVE-2024-9472, upgrade to the fixed versions of PAN-OS or other affected products as specified by Palo Alto Networks.
Which products are affected by CVE-2024-9472?
CVE-2024-9472 affects Palo Alto Networks PAN-OS, Cloud NGFW, and Prisma Access on specific hardware platforms.
What exploit vector is associated with CVE-2024-9472?
CVE-2024-9472 can be exploited by an unauthenticated attacker sending specific traffic through the data plane.
What impact does CVE-2024-9472 have on systems?
The impact of CVE-2024-9472 is that it allows an attacker to crash PAN-OS, resulting in a denial of service.