QID 731373
Date Published: 2024-04-11
QID 731373: Palo Alto Networks (PAN-OS) Firewall Denial of Service (DoS) via a Burst of Crafted Packets Vulnerability (PAN-234921)
PAN OS is the software that runs all Palo Alto Networks next-generation firewalls.
A memory leak exists in Palo Alto Networks PAN-OS software that enables an attacker to send a burst of crafted packets through the firewall that eventually prevents the firewall from processing traffic. This issue applies only to PA-5400 Series devices that are running PAN-OS software with the SSL Forward Proxy feature enabled.
Affected Versions:
PAN-OS 11.1 versions earlier than PAN-OS 11.1.2
PAN-OS 11.0 versions earlier than PAN-OS 11.0.4
PAN-OS 10.2 versions earlier than PAN-OS 10.2.7-h3
QID Detection Logic (Authenticated):
This QID looks for the vulnerable version of PAN-OS
NOTE:You can mitigate this issue by disabling decryption on your firewalls.To temporarily disable SSL Decryption, refer to the administrators guide for your PAN-OS software.Additionally, to ensure that decryption remains disabled after a reboot, configure a policy-based decryption exclusion that excludes all traffic from being decrypted
A memory leak exists in Palo Alto Networks PAN-OS software that enables an attacker to send a burst of crafted packets through the firewall that eventually prevents the firewall from processing traffic. This issue applies only to PA-5400 Series devices that are running PAN-OS software with the SSL Forward Proxy feature enabled.
Refer to CVE-2024-3382 for more information about patching this vulnerability.
Workaround:
You can mitigate this issue by disabling decryption on your firewalls. To temporarily disable SSL Decryption, refer to the administrators guide for your PAN-OS software (such as PAN-OS 11.1: https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-admin/decryption/temporarily-disable-ssl-decryption). Additionally, to ensure that decryption remains disabled after a reboot, configure a policy-based decryption exclusion that excludes all traffic from being decrypted (https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-admin/decryption/decryption-exclusions/create-a-policy-based-decryption-exclusion).
- PAN-234921 -
security.paloaltonetworks.com/CVE-2024-3382
CVEs related to QID 731373
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| CVE-2024-3382 |
|