← Vulnerability feed

Vulnerability record · CVE-2024-3393 · published 27 December 2024

CVE-2024-3393: PAN-OS DNS Security packet causes firewall reboot and maintenance mode

Paloaltonetworks · Pan Os

A denial of service flaw in the DNS Security feature of Palo Alto Networks PAN-OS lets an unauthenticated attacker send a crafted packet through the firewall data plane that reboots the device. Repeated triggers push the firewall into maintenance mode, taking it fully offline. Because the firewall is a perimeter control, this can disrupt all protected traffic, not just DNS inspection.

8.7 CVSS 4.0 High CISA KEV since 30 Dec 2024 EPSS 28% · top 1.9% CWE-754 · CWE-754
8.7CVSS 4.0 base score
28%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
2Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

A Denial of Service vulnerability in the DNS Security feature of Palo Alto Networks PAN-OS software allows an unauthenticated attacker to send a malicious packet through the data plane of the firewall that reboots the firewall. Repeated attempts to trigger this condition will cause the firewall to enter maintenance mode.

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

high priorityUnauthenticated remote denial of service against a perimeter firewall, with confirmed KEV exploitation and high EPSS, though impact is availability only.

What it is

A denial of service flaw in the DNS Security feature of Palo Alto Networks PAN-OS lets an unauthenticated attacker send a crafted packet through the firewall data plane that reboots the device. Repeated triggers push the firewall into maintenance mode, taking it fully offline. Because the firewall is a perimeter control, this can disrupt all protected traffic, not just DNS inspection.

Impact

An attacker can repeatedly reboot a targeted firewall and force it into maintenance mode, causing sustained loss of availability for the network it protects. No data is read or altered; the gain is purely denial of service.

Attack surface

Reachable over the network through the data plane with no authentication and no user interaction, per the CVSS 4.0 vector (AV:N/PR:N/UI:N). The DNS Security feature must be in use for the malicious packet to be processed.

Exploitation

Listed in CISA KEV with a due date of 2025-01-20, indicating known exploitation in the wild. EPSS is 0.284 (98th percentile), so short-term exploitation likelihood is elevated.

What to do

  • Apply the vendor fix from the Palo Alto Networks advisory for CVE-2024-3393; patch is the primary action.
  • If patching cannot be done immediately, follow the vendor's stated mitigations or disable the affected DNS Security functionality until fixed.
  • Restrict management and data-plane exposure of PAN-OS firewalls to trusted networks where operationally possible.
  • Monitor for repeated firewall reboots or unexpected maintenance-mode transitions and treat them as potential attack activity.
  • Track the CISA KEV due date of 2025-01-20 and confirm remediation before it lapses.

Detection

  • Alert on unexpected PAN-OS reboots or transitions into maintenance mode, especially clustered or repeated events.
  • Review firewall and system logs for DNS Security processing anomalies or crashes correlated with inbound DNS traffic.
  • Baseline normal reboot cadence and flag deviations; correlate with spikes in DNS packets to the data plane.
  • Check for repeated reboot cycles within short windows that match the repeated-trigger pattern described in the advisory.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2024-3393 to the Known Exploited Vulnerabilities catalog on 30 December 2024 as "Palo Alto Networks PAN-OS Malicious DNS Packet Vulnerability". Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Federal deadline 20 January 2025.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-3393 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2024-3400PAN-OS GlobalProtect command injection allows unauthenticated root code executionA command injection caused by arbitrary file creation in the GlobalProtect feature of Palo Alto Networks PAN-OS lets an unauthenticated attacker run …KEVEPSS 100%analysed10.0CVE-2020-2021PAN-OS SAML signature verification bypass allows authentication bypassPAN-OS fails to properly verify SAML signatures when SAML authentication is enabled and the 'Validate Identity Provider Certificate' option is unchec…KEVEPSS 4.4%analysed9.8CVE-2017-15944PAN-OS management interface input validation flaw allows remote code executionPAN-OS versions before 6.1.19, 7.0.x before 7.0.19, 7.1.x before 7.1.14, and 8.0.x before 8.0.6 contain an input validation and memory buffer overflo…KEVEPSS 98%analysed9.3CVE-2026-0300PAN-OS User-ID Authentication Portal buffer overflow allows root code executionA buffer overflow (out-of-bounds write, CWE-787) in the User-ID Authentication Portal (Captive Portal) service of Palo Alto Networks PAN-OS lets an u…KEVEPSS 32%analysed9.3CVE-2024-0012PAN-OS Management Web Interface Authentication BypassPAN-OS contains a missing authentication flaw (CWE-306) in the management web interface that lets an unauthenticated network attacker obtain PAN-OS a…KEVEPSS 100%analysed8.8CVE-2025-0108PAN-OS management web interface authentication bypassPAN-OS contains a missing-authentication flaw (CWE-306) in the management web interface that lets an unauthenticated attacker with network access inv…KEVEPSS 98%analysed8.6CVE-2022-0028PAN-OS URL filtering misconfiguration enables reflected TCP DoSA PAN-OS URL filtering policy misconfiguration allows a network-based attacker to use PA-Series, VM-Series and CN-Series firewalls to conduct reflect…KEVEPSS 2.4%analysed8.1CVE-2019-1579PAN-OS GlobalProtect pre-auth remote code executionPAN-OS versions 7.1.18, 8.0.11-h1 and 8.1.2 and earlier contain a remote code execution flaw (CWE-134, format string) that is reachable when the Glob…KEVEPSS 46%analysed

Source: NIST National Vulnerability Database (record CVE-2024-3393), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.