QID 731370
Date Published: 2024-04-11
QID 731370: Palo Alto Networks (PAN-OS) Predefined Decryption Exclusions Does Not Work as Intended Vulnerability (PAN-208155)
PAN OS is the software that runs all Palo Alto Networks next-generation firewalls.
An incorrect string comparison vulnerability in Palo Alto Networks PAN-OS software prevents Predefined Decryption Exclusions from functioning as intended. This can cause traffic destined for domains that are not specified in Predefined Decryption Exclusions to be unintentionally excluded from decryption.
Affected Versions:
PAN-OS 11.0 versions earlier than PAN-OS 11.0.1-h2,
PAN-OS 10.2 versions earlier than PAN-OS 10.2.4-h2,
PAN-OS 10.1 versions earlier than PAN-OS 10.1.9-h3,
PAN-OS 10.0 versions earlier than PAN-OS 10.0.13
PAN-OS 9.1 versions earlier than PAN-OS 9.1.17
PAN-OS 9.0 versions earlier than PAN-OS 9.0.17-h2
QID Detection Logic (Authenticated):
This QID looks for the vulnerable version of PAN-OS
An incorrect string comparison vulnerability in Palo Alto Networks PAN-OS software prevents Predefined Decryption Exclusions from functioning as intended. This can cause traffic destined for domains that are not specified in Predefined Decryption Exclusions to be unintentionally excluded from decryption.
Refer to CVE-2024-3386 for more information about patching this vulnerability.
- PAN-208155 -
security.paloaltonetworks.com/CVE-2024-3386
CVEs related to QID 731370
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| CVE-2024-3386 |
|