CVE-2024-3393 PAN-OS: Firewall Denial of Service (DoS) in DNS Security Using a Specially Crafted Packet
Incident Report for Palo Alto Networks Cloud Services
Monitoring
“Customers using DNS security logging are at risk of a ‘Denial of Service’ vulnerability, allowing attackers to send a malicious packet through the firewall’s data plane, triggering a reboot. Affected customers will receive an insights notification and will be scheduled for an upgrade starting the weekend of January 3rd, 2025. In the meantime, we strongly recommend implementing the workaround detailed at https://security.paloaltonetworks.com/CVE-2024-3393 to mitigate the risk.”
Posted Dec 27, 2024 - 18:58 UTC