PAN-OS

CVE-2024-3393: Firewall Denial of Service (DoS) in DNS Security Using a Specially Crafted Packet

A Denial of Service vulnerability in the DNS Security feature of Palo Alto Networks PAN-OS software allows an unauthenticated attacker to send a malicious packet through the data plane of the firewall that reboots the firewall.

Published

ExploitedYes, in CISA KEVAdded 30 Dec 2024
Ransomware useNot reportedPer CISA
SeverityHIGHCVSS 4.0 8.7
EPSS29%Chance of exploitation in 30 days
Public exploitNot tracked
FixAvailable

Automatic summary from the vendor's CVE record. We haven't written a full analysis of this vulnerability yet.

Affected and fixed versions

Product / branchFixed in
Cloud NGFWNot affected
PAN-OS 11.211.2.3 or later
PAN-OS 11.111.1.2-h16, 11.1.3-h13, 11.1.4-h7, 11.1.5 or later
PAN-OS 9.1, 10.0, 10.1, 10.2Not affected
PAN-OS (Prisma Access) 10.2Not affected
PAN-OS (Prisma Access) 11.211.2.3 or later
PAN-OS (Panorama)Not affected

Always confirm against the vendor advisory, which lists every fixed hotfix.

What it is

A Denial of Service vulnerability in the DNS Security feature of Palo Alto Networks PAN-OS software allows an unauthenticated attacker to send a malicious packet through the data plane of the firewall that reboots the firewall. Repeated attempts to trigger this condition will cause the firewall to enter maintenance mode.

This issue is applicable to the PAN-OS software versions listed below on PA-Series firewalls, VM-Series firewalls, CN-Series firewalls, and Prisma Access.

Am I affected?

This issue does not affect Cloud NGFW, Panorama M-Series, or Panorama virtual appliances.

Both of the following must be true for PAN-OS software to be affected:

  1. Either a DNS Security License or an Advanced DNS Security License must be applied, AND
  2. DNS Security logging must be enabled.

You can check for existing DNS Security Configuration in your firewalls using the PAN-OS CLI:

> show config merged | match log-level

  • Look for entries with the string 'log-level':
  • If no entries are found (output is empty) or all entries show 'log-level none;', your configuration is not vulnerable, and no workaround is needed.
  • If any entries show values other than 'log-level none;', your configuration is vulnerable. You should either upgrade PAN-OS or follow the steps in the workaround section.

Workarounds

If your firewall running the vulnerable PAN-OS versions stops responding or reboots unexpectedly and you cannot immediately apply a fix, apply a workaround below based on your deployment.

Unmanaged NGFWs, NGFW managed by Panorama, or Prisma Access managed by Panorama

  1. Ensure that a DNS Security Configuration is already present in the device's configuration. See the "Required Configuration for Exposure" section for details.
  2. Within Objects → Security Profiles (https://docs.paloaltonetworks.com/pan-os/11-2/pan-os-web-interface-help/objects/objects-security-profiles-anti-spyware-profile), determine if you use the predefined Anti-Spyware profiles (https://docs.paloaltonetworks.com/network-security/security-policy/administration/security-profiles/security-profile-anti-spyware) in your Security Policy. These are named "Default" or "Strict" (https://docs.paloaltonetworks.com/network-security/security-policy/administration/security-profiles/security-profile-anti-spyware). If you are using the predefined security profiles, clone the predefined Anti-Spyware profile (https://docs.paloaltonetworks.com/pan-os/11-2/pan-os-web-interface-help/objects/move-clone-override-or-revert-objects/move-or-clone-an-object) for use as a custom Anti-Spyware profile. After cloning each relevant predefined Anti-Spyware profile, replace them with the cloned custom Anti-Spyware profile or group in your Security Rules (Policies → Security → (security rule) in either Actions → Profiles or Actions → Group (https://docs.paloaltonetworks.com/network-security/security-policy/administration/security-rules/create-a-security-policy-rule#create-a-security-policy-rule-panorama)).
  1. For each custom Anti-Spyware profile, navigate to Objects → Security Profiles → Anti-Spyware → (select a custom profile) → DNS Policies → DNS Security.
  2. Change the Log Severity to "none" for all configured DNS Security categories.
  1. Commit the changes.

Note 1: Setting Log Severity to 'none' for devices that didn't have a DNS Security configuration may block DNS traffic that wasn’t previously blocked. Additionally, this may happen without generating any log entries, making it difficult to detect the blocked traffic. Review the Required Configuration for Exposure section for instructions on identifying existing DNS Security Configuration.

Note 2: Remember to revert the Log Severity settings once the fixes are applied.

NGFW managed by Strata Cloud Manager (SCM)

You can choose one of the following mitigation options: 1. Option 1: Disable DNS Security logging directly on each NGFW by following the PAN-OS steps above. 2. Option 2: Disable DNS Security logging across all NGFWs in your tenant by opening a support case (https://support.paloaltonetworks.com/Support/Index).

Prisma Access managed by Strata Cloud Manager (SCM)

Until we perform an upgrade of your Prisma Access tenant, you can disable DNS Security logging across all NGFWs in your tenant by opening a support case (https://support.paloaltonetworks.com/Support/Index). If you would like to expedite the upgrade, please make a note of that in the support case.

Exploitation

Palo Alto Networks is aware of customers experiencing this denial of service (DoS) when their firewall blocks malicious DNS packets that trigger this issue.

CISA lists this CVE as exploited in the wild since 30 Dec 2024.

Sources

KEV status, EPSS score and vendor data refreshed automatically, last on 10 Oct 2026.

Get alerts

A notification when we publish a new analysis or a covered vendor gets a new actively exploited CVE. No account, no email.