Executive brief
Palo Alto Networks Prisma SD-WAN ION devices, which are used to manage and secure corporate wide-area networks, are vulnerable to a denial-of-service attack. An attacker on the same local network can send a specifically crafted IPv6 packet to crash or disrupt the device. This could lead to network outages and loss of connectivity for affected branch offices or data centers.
Technical details
A denial of service (DoS) vulnerability exists in Palo Alto Networks Prisma SD-WAN ION devices due to unchecked input for a loop condition (CWE-606) when processing IPv6 traffic. An unauthenticated attacker located in the same adjacent network (Layer 2) can exploit this by sending a specially crafted IPv6 packet to the device. Successful exploitation results in system disruption or a complete denial of service. The vulnerability requires IPv6 to be enabled on the device. Patches are available in versions 6.3.6-b10, 6.4.3-b8, and 6.5.3-b15 or later.
Affected products
- Palo Alto Networks Prisma SD-WAN ION 6.3 < 6.3.6-b10, 6.4 < 6.4.3-b8, 6.5 < 6.5.3-b15
Timeline
- 2026-05-13: disclosed: Initial publication by Palo Alto Networks
- 2026-05-13: advisory