CVE-2024-3385
PAN-OS: Firewall Denial of Service (DoS) when GTP Security is Disabled
Severity
High 7.5
CVSS 3.1
Exploited
Not listed
EPSS
0.009
56.5th percentile
Discovered by
Third party
Published by the vendor
Published
Apr 10, 2024
Assigned by palo_alto
Description
A packet processing mechanism in Palo Alto Networks PAN-OS software enables a remote attacker to reboot hardware-based firewalls. Repeated attacks eventually cause the firewall to enter maintenance mode, which requires manual intervention to bring the firewall back online. This affects the following hardware firewall models: - PA-5400 Series firewalls - PA-7000 Series firewalls
Weakness: CWE-20CWE-476
Affected products
| Vendor | Product | Category | Matched by |
|---|---|---|---|
| Palo Alto Networks | Cloud NGFW | Firewall / NGFW | cna-assigner |
| Palo Alto Networks | PAN-OS | Firewall / NGFW | cna-assigner |
| Palo Alto Networks | Prisma Access | SASE / SSE / Secure Web | cna-assigner |
Vendor-reported affected versions (3)
- Palo Alto Networks · PAN-OS
- Palo Alto Networks · Cloud NGFW
- Palo Alto Networks · Prisma Access
Credit
Palo Alto Networks thanks an external reporter for discovering and reporting this issue.
Vendor remediation
This issue is fixed in PAN-OS 9.0.17-h4, PAN-OS 9.1.17, PAN-OS 10.1.12, PAN-OS 10.2.8, PAN-OS 11.0.3, and all later PAN-OS versions.