CVE-2024-3386Medium

CVE-2024-3386 PAN-OS: Predefined Decryption Exclusions Does Not Work as Intended

Published
April 10, 2024
Last Modified
April 10, 2024

🔗 CVE IDs covered (1)

📋 Description

An incorrect string comparison vulnerability in Palo Alto Networks PAN-OS software prevents Predefined Decryption Exclusions from functioning as intended. This can cause traffic destined for domains that are not specified in Predefined Decryption Exclusions to be unintentionally excluded from decryption.

🎯 Affected products3

  • PAN-OS
  • Cloud NGFW
  • Prisma Access

✅ Remediation

This issue is fixed in 9.0.17-h2, 9.0.18, 9.1.17, 10.0.13, 10.1.9-h3, 10.1.10, 10.2.4-h2, 10.2.5, 11.0.1-h2, 11.0.2, and all later PAN-OS versions.

🔗 References (1)