CVE-2024-3393 is a Denial of Service vulnerability in Palo Alto Networks PAN-OS and Prisma Access, allowing unauthenticated attackers to reboot firewalls via a malicious DNS packet. With a CVSS score of 7.5 (High), this easily exploitable flaw requires no user interaction and can force affected devices into maintenance mode. This vulnerability is actively exploited in the wild, as confirmed by its inclusion in CISA's KEV catalog, and has garnered significant community and media attention, despite no public exploit code being available.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 11.1.0, <= 11.1.1CPE matchmatch criteria | cpe:2.3:o:paloaltonetworks:pan-os:*:*:*:*:*:*:*:* | ||
>= 11.2.0, < 11.2.3CPE matchmatch criteria | cpe:2.3:o:paloaltonetworks:pan-os:*:*:*:*:*:*:*:* | ||
10.1.14CPE matchmatch criteria | cpe:2.3:o:paloaltonetworks:pan-os:10.1.14:-:*:*:*:*:*:* | ||
10.1.14CPE matchmatch criteria | cpe:2.3:o:paloaltonetworks:pan-os:10.1.14:h2:*:*:*:*:*:* | ||
10.1.14CPE matchmatch criteria | cpe:2.3:o:paloaltonetworks:pan-os:10.1.14:h4:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:C/RE:M/U:Amber
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.