>> All posts

CVE-2024-3393: Palo Alto PAN-OS DNS Security denial-of-service, actively exploited

The short version: CVE-2024-3393 is a denial-of-service flaw in the DNS Security feature of PAN-OS. An unauthenticated attacker can send a malicious packet through the firewall's data plane that causes it to reboot — and repeated attempts drive it into maintenance mode, taking your perimeter offline. It's confirmed exploited and in CISA's KEV catalog. It doesn't breach the device, but it can knock it out. Steady hands — but move.

At a glance

FactDetail
Our severity takeHigh — a direct outage of your own perimeter (see below)
CVSS v3.1 (NVD)7.5 — High · AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS (Palo Alto)8.7 — High
EPSS~26.64% · 97.80th percentile (2026-07-17)
In CISA KEV?Yes — remediate by 2025-01-20
Known exploited?Yes — customers experienced DoS reboots when the firewall blocked malicious DNS packets
Vulnerability typeCWE-754 improper check for unusual or exceptional conditions → unauthenticated denial of service (reboot → maintenance mode)
Requires authenticated session?No — pre-authentication
AffectedPAN-OS 10.1, 10.2, 11.1, and 11.2 branches with DNS Security logging enabled — see Palo Alto's advisory for exact builds
Fixed inPAN-OS 10.1.15 · 10.2.14 · 11.1.5 · 11.2.3 (and relevant hotfixes / later) — Cloud NGFW unaffected

What you need to know

PAN-OS DNS Security inspects and logs DNS traffic. CVE-2024-3393 is a flaw in how it parses and logs a malicious DNS packet: an attacker sends crafted traffic through the data plane, the firewall mishandles it, and the device reboots. Send it repeatedly and the firewall enters maintenance mode — a sustained outage that requires intervention to recover.

  • How they find it — internet-wide scanning surfaces exposed PAN-OS devices; the DNS Security configuration determines susceptibility.
  • How they use it — malicious DNS packets sent through the data plane to force reboots.
  • What it leads to — repeated reboots and maintenance mode: your perimeter firewall down, not compromised.

How serious we see it

High — with an honest framing.

This is availability only: no data access, no code execution, no configuration change. But it's a direct denial of service against your own perimeter device, it's actively exploited, and it's KEV-listed. A firewall stuck in maintenance mode is your primary control offline — an operational emergency even without a breach. So we treat it as High for the outage risk, while being clear it isn't a compromise. The bounded, reassuring part: it affects specific builds, Cloud NGFW isn't affected, fixes are out, and exposure is quick to determine.

Recommendations

Straight from Palo Alto's advisory and CISA:

  1. Patch now. Upgrade to a fixed PAN-OS build (e.g. 10.1.15 / 10.2.14 / 11.1.5 / 11.2.3 or the relevant hotfix / later).
  2. Apply the interim mitigation if you can't patch immediately. Follow Palo Alto's guidance to adjust DNS Security logging behavior as a stopgap.
  3. Monitor for reboots. Alert on unexpected firewall restarts and maintenance-mode transitions.
  4. Confirm your exposure first. Verify whether you run an affected PAN-OS build with DNS Security enabled.

How BreachRisk sees it

BreachRisk discovers internet-facing Palo Alto devices from little more than your domain, fingerprints the PAN-OS product and version, and flags exposure tied to KEV-listed, actively exploited vulnerabilities like this one so it rises to the top of your results.

That continuous, outside-in view means the exposed device is already mapped and version-fingerprinted when a firewall DoS lands in KEV — so you can go straight to patch-and-verify instead of starting from an inventory.

References

See your cyber risk, proven.