CVE-2024-9468

PAN-OS: Firewall Denial of Service (DoS) via a Maliciously Crafted Packet

Severity
High 8.2
CVSS 4.0
Exploited
Not listed
EPSS
0.004
33.7th percentile
Discovered by
Vendor
Published by the vendor
Published
Oct 9, 2024
Assigned by palo_alto

Description

A memory corruption vulnerability in Palo Alto Networks PAN-OS software allows an unauthenticated attacker to crash PAN-OS due to a crafted packet through the data plane, resulting in a denial of service (DoS) condition. Repeated attempts to trigger this condition will result in PAN-OS entering maintenance mode.

Weakness: CWE-787

Affected products

Vendor Product Category Matched by
Palo Alto Networks Cloud NGFW Firewall / NGFW cna-assigner
Palo Alto Networks PAN-OS Firewall / NGFW cna-assigner
Palo Alto Networks Prisma Access SASE / SSE / Secure Web cna-assigner
Vendor-reported affected versions (3)
  • Palo Alto Networks · Cloud NGFW
  • Palo Alto Networks · PAN-OS
  • Palo Alto Networks · Prisma Access

Credit

Jeff Luo of Palo Alto Networks

Vendor remediation

This issue is fixed in 10.2.9-h11, 10.2.10-h4, PAN-OS 10.2.11, PAN-OS 11.0.4-h5, PAN-OS 11.0.6, PAN-OS 11.1.3, and all later PAN-OS versions.