CVE-2026-0243: Prisma SD-WAN: Denial of Service (DoS) Vulnerability Through IPv6 Crafted Packet (Severity: MEDIUM)
A denial of service (DoS) vulnerability in Palo Alto Networks Prisma SD-WAN ION devices enables an unauthenticated attacker in a network adjacent to a Prisma SD-WAN ION device to cause a system disruption by sending a specially crafted IPv6 packet.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.5.3-b15Fixed in 6.4.3-b8Fixed in 6.3.6-b10 - Upgrade
Upgrade
Palo Alto Networks Prisma SD-WAN ION 6.3to a version that resolves this vulnerability.Fixed in 6.3.6-b10 - Upgrade
Upgrade
Palo Alto Networks Prisma SD-WAN ION 6.4to a version that resolves this vulnerability.Fixed in 6.4.3-b8 - Upgrade
Upgrade
Palo Alto Networks Prisma SD-WAN ION 6.5to a version that resolves this vulnerability.Fixed in 6.5.3-b15 - Configuration
Disable IPv6 on Prisma SD-WAN ION devices if not required.
Palo Alto Networks Prisma SD-WAN ION IPv6 = disabled
Event History
Frequently Asked Questions
What is the severity of CVE-2026-0243?
The severity of CVE-2026-0243 is classified as MEDIUM.
How does CVE-2026-0243 affect Prisma SD-WAN ION devices?
CVE-2026-0243 allows an unauthenticated attacker to perform a denial of service on Prisma SD-WAN ION devices.
What versions of Prisma SD-WAN ION are affected by CVE-2026-0243?
Prisma SD-WAN ION versions 6.5.0, 6.4.0, and 6.3.0 are affected by CVE-2026-0243.
How can I mitigate the risk of CVE-2026-0243?
Updating to the remedied versions 6.5.3-b15, 6.4.3-b8, or 6.3.6-b10 can mitigate the risk of CVE-2026-0243.
Is authentication required to exploit CVE-2026-0243?
No, CVE-2026-0243 can be exploited by an unauthenticated attacker.