CVE-2024-3383 is a critical vulnerability in Palo Alto Networks PAN-OS software that allows for the modification of User-ID groups due to improper processing of data from Cloud Identity Engine (CIE) agents. This flaw, rated 9.1 CVSS, can lead to unauthorized access or denial of service to network resources by incorrectly applying security policies. While no public exploits or active exploitation have been observed, the vulnerability has garnered some community discussion and media coverage, indicating awareness within the cybersecurity landscape.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 10.1.0, < 10.1.11CPE matchmatch criteria | cpe:2.3:o:paloaltonetworks:pan-os:*:*:*:*:*:*:*:* | ||
>= 10.2.0, < 10.2.5CPE matchmatch criteria | cpe:2.3:o:paloaltonetworks:pan-os:*:*:*:*:*:*:*:* | ||
>= 11.0.0, < 11.0.3CPE matchmatch criteria | cpe:2.3:o:paloaltonetworks:pan-os:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.