Executive brief
A security vulnerability exists in the DNS features of Palo Alto Networks firewalls, which are used to manage and secure network traffic. An attacker could exploit this flaw to crash the device, causing a network outage, or potentially take full control of certain hardware models. This issue primarily affects organizations using the DNS Proxy feature or those connected to compromised DNS servers.
Technical details
A heap-based buffer overflow (CWE-122) exists in the DNS proxy and DNS Server features of Palo Alto Networks PAN-OS. The vulnerability is triggered when the DNS Proxy is enabled and attached to a network interface, or when the firewall is configured to use a compromised public DNS server. An unauthenticated remote attacker can exploit this by sending specially crafted network traffic. On PA-Series hardware, this may lead to arbitrary code execution; on VM-Series and other platforms, the impact is typically limited to a denial of service (DoS). Patches are available for PAN-OS 10.2, 11.1, 11.2, and 12.1.
Affected products
- Palo Alto Networks PAN-OS 12.1 < 12.1.4-h5, 12.1 < 12.1.7, 11.2 < 11.2.4-h17, 11.2 < 11.2.7-h13, 11.2 < 11.2.10-h6, 11.2 < 11.2.12, 11.1 < 11.1.4-h33, 11.1 < 11.1.6-h32, 11.1 < 11.1.7-h6, 11.1 < 11.1.10-h25, 11.1 < 11.1.13-h5, 11.1 < 11.1.15, 10.2 < 10.2.7-h34, 10.2 < 10.2.10-h36, 10.2 < 10.2.13-h21, 10.2 < 10.2.16-h7, 10.2 < 10.2.18-h6
- Siemens RUGGEDCOM APE1808 All versions with Palo Alto Networks Virtual NGFW with DNS Proxy enabled
Timeline
- 2026-05-13: advisory: Initial advisory published by Palo Alto Networks
- 2026-05-13: disclosed
- 2026-05-28: other: Advisory updated by Palo Alto Networks
- 2026-06-09: other: Siemens advisory updated regarding RUGGEDCOM APE1808 devices