QID 731372
Date Published: 2024-04-11
QID 731372: Palo Alto Networks (PAN-OS) Firewall Denial of Service (DoS) when GTP Security is Disabled Vulnerability (PAN-221224)
PAN OS is the software that runs all Palo Alto Networks next-generation firewalls.
A packet processing mechanism in Palo Alto Networks PAN-OS software enables a remote attacker to reboot hardware-based firewalls. Repeated attacks eventually cause the firewall to enter maintenance mode, which requires manual intervention to bring the firewall back online.
Affected Versions:
PAN-OS 11.0 versions earlier than PAN-OS 11.0.3
PAN-OS 10.2 versions earlier than PAN-OS 10.2.8
PAN-OS 10.1 versions earlier than PAN-OS 10.1.12
PAN-OS 9.1 versions earlier than PAN-OS 9.1.17
PAN-OS 9.0 versions earlier than PAN-OS 9.0.17-h4
QID Detection Logic (Authenticated):
This QID looks for the vulnerable version of PAN-OS
NOTE:This does not affect VM-Series firewalls, CN-Series firewalls, Cloud NGFWs, or Prisma Access.
Customers with a Threat Prevention subscription can block attacks for this vulnerability by enabling Threat ID 94993 (introduced in Applications and Threats content version 8832)
A packet processing mechanism in Palo Alto Networks PAN-OS software enables a remote attacker to reboot hardware-based firewalls. Repeated attacks eventually cause the firewall to enter maintenance mode, which requires manual intervention to bring the firewall back online.
Refer to CVE-2024-3385 for more information about patching this vulnerability.
Workaround:
Customers with a Threat Prevention subscription can block attacks for this vulnerability by enabling Threat ID 94993 (introduced in Applications and Threats content version 8832).
- PAN-221224 -
security.paloaltonetworks.com/CVE-2024-3385
CVEs related to QID 731372
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| CVE-2024-3385 |
|