← Back to browse · API

CVE-2024-3393

Severity
HIGH
CVSS
8.7
EPSS
0.28617
Risk score
69.82
CISA KEV
Yes
PoC
No
Published
2024-12-27
Modified
2025-10-21
First seen
2026-08-07
Aliases
EUVD-2024-31982, GHSA-GM94-VR86-WGQV
Products
Palo Alto Networks:PAN-OS, Palo Alto Networks:PAN-OS 10.1.14 <10.1.14-h8, Palo Alto Networks:PAN-OS 10.2.8 <10.2.8-h19, Palo Alto Networks:PAN-OS 11.1.0 <11.1.2-h16, Palo Alto Networks:PAN-OS 11.2.0 <11.2.3
Sources
cisa.gov CVE-2024-3393
euvd EUVD-2024-31982

Description

A Denial of Service vulnerability in the DNS Security feature of Palo Alto Networks PAN-OS software allows an unauthenticated attacker to send a malicious packet through the data plane of the firewall that reboots the firewall. Repeated attempts to trigger this condition will cause the firewall to enter maintenance mode.

References