Executive brief
A Denial of Service vulnerability in the DNS Security feature of Palo Alto Networks PAN-OS allows an unauthenticated remote attacker to reboot the firewall by sending malicious DNS packets through the data plane. Repeated exploitation can force the device into maintenance mode, requiring manual intervention.
Affected products
- Palo Alto Networks PAN-OS 10.1.14, 10.2.8 through 10.2.11, 11.2.x before 11.2.3
- Palo Alto Networks Prisma Access
Timeline
- 2024-12-30: disclosed
- 2024-12-30: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2024-12-30: exploited: Reported as exploited in the wild at time of publication.