CVE-2024-3393: Palo Alto PAN-OS DNS Security denial-of-service, actively exploited
The short version: CVE-2024-3393 is a denial-of-service flaw in the DNS Security feature of PAN-OS. An unauthenticated attacker can send a malicious packet through the firewall's data plane that causes it to reboot — and repeated attempts drive it into maintenance mode, taking your perimeter offline. It's confirmed exploited and in CISA's KEV catalog. It doesn't breach the device, but it can knock it out. Steady hands — but move.
At a glance
| Fact | Detail |
|---|---|
| Our severity take | High — a direct outage of your own perimeter (see below) |
| CVSS v3.1 (NVD) | 7.5 — High · AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
| CVSS (Palo Alto) | 8.7 — High |
| EPSS | ~26.64% · 97.80th percentile (2026-07-17) |
| In CISA KEV? | Yes — remediate by 2025-01-20 |
| Known exploited? | Yes — customers experienced DoS reboots when the firewall blocked malicious DNS packets |
| Vulnerability type | CWE-754 improper check for unusual or exceptional conditions → unauthenticated denial of service (reboot → maintenance mode) |
| Requires authenticated session? | No — pre-authentication |
| Affected | PAN-OS 10.1, 10.2, 11.1, and 11.2 branches with DNS Security logging enabled — see Palo Alto's advisory for exact builds |
| Fixed in | PAN-OS 10.1.15 · 10.2.14 · 11.1.5 · 11.2.3 (and relevant hotfixes / later) — Cloud NGFW unaffected |
What you need to know
PAN-OS DNS Security inspects and logs DNS traffic. CVE-2024-3393 is a flaw in how it parses and logs a malicious DNS packet: an attacker sends crafted traffic through the data plane, the firewall mishandles it, and the device reboots. Send it repeatedly and the firewall enters maintenance mode — a sustained outage that requires intervention to recover.
- How they find it — internet-wide scanning surfaces exposed PAN-OS devices; the DNS Security configuration determines susceptibility.
- How they use it — malicious DNS packets sent through the data plane to force reboots.
- What it leads to — repeated reboots and maintenance mode: your perimeter firewall down, not compromised.
How serious we see it
High — with an honest framing.
This is availability only: no data access, no code execution, no configuration change. But it's a direct denial of service against your own perimeter device, it's actively exploited, and it's KEV-listed. A firewall stuck in maintenance mode is your primary control offline — an operational emergency even without a breach. So we treat it as High for the outage risk, while being clear it isn't a compromise. The bounded, reassuring part: it affects specific builds, Cloud NGFW isn't affected, fixes are out, and exposure is quick to determine.
Recommendations
Straight from Palo Alto's advisory and CISA:
- Patch now. Upgrade to a fixed PAN-OS build (e.g. 10.1.15 / 10.2.14 / 11.1.5 / 11.2.3 or the relevant hotfix / later).
- Apply the interim mitigation if you can't patch immediately. Follow Palo Alto's guidance to adjust DNS Security logging behavior as a stopgap.
- Monitor for reboots. Alert on unexpected firewall restarts and maintenance-mode transitions.
- Confirm your exposure first. Verify whether you run an affected PAN-OS build with DNS Security enabled.
How BreachRisk sees it
BreachRisk discovers internet-facing Palo Alto devices from little more than your domain, fingerprints the PAN-OS product and version, and flags exposure tied to KEV-listed, actively exploited vulnerabilities like this one so it rises to the top of your results.
That continuous, outside-in view means the exposed device is already mapped and version-fingerprinted when a firewall DoS lands in KEV — so you can go straight to patch-and-verify instead of starting from an inventory.