CVE-2024-3385High

CVE-2024-3385 PAN-OS: Firewall Denial of Service (DoS) when GTP Security is Disabled

Published
April 10, 2024
Last Modified
April 10, 2024

🔗 CVE IDs covered (1)

📋 Description

A packet processing mechanism in Palo Alto Networks PAN-OS software enables a remote attacker to reboot hardware-based firewalls. Repeated attacks eventually cause the firewall to enter maintenance mode, which requires manual intervention to bring the firewall back online. This affects the following hardware firewall models:

  • PA-5400 Series firewalls
  • PA-7000 Series firewalls

🎯 Affected products3

  • PAN-OS
  • Cloud NGFW
  • Prisma Access

✅ Remediation

This issue is fixed in PAN-OS 9.0.17-h4, PAN-OS 9.1.17, PAN-OS 10.1.12, PAN-OS 10.2.8, PAN-OS 11.0.3, and all later PAN-OS versions. Workarounds and mitigations: Customers with a Threat Prevention subscription can block attacks for this vulnerability by enabling Threat ID 94993 (introduced in Applications and Threats content version 8832).

🔗 References (1)