Palo Alto Networks has revealed a high severity vulnerability in PAN-OS software that may lead to a denial-of-service (DoS) issue on affected devices.
The vulnerability CVE-2024-3393 (CVSS score: 8.7) affects PAN-OS versions 10.X and 11.X, and Prisma Access with PAN-OS versions 10.2.8 or later and before 11.2.3. It has been fixed in PAN-OS versions 10.1.14-h8, 10.2.10-h12, 11.1.5, 11.2.3, and all newer versions.
By infosecbulletin
/ Friday , December 27 2024
Palo Alto Networks has revealed a high severity vulnerability in PAN-OS software that may lead to a denial-of-service (DoS) issue...
Read More
By infosecbulletin
/ Friday , December 27 2024
Japan Airlines reported a cyberattack on Thursday that delayed over 20 domestic flights. The airline managed to stop the attack...
Read More
By infosecbulletin
/ Thursday , December 26 2024
Hackers claimed to have accessed and stolen 82 GB of sensitive data from Indonesia's Regional Financial Management Information System (SIPKD)....
Read More
By infosecbulletin
/ Wednesday , December 25 2024
Bangladesh Cyber Security Intelligence (BCSI) officially launch the National Vulnerability Disclosure Program (NVDP) to enhance the country's cybersecurity. This initiative...
Read More
By infosecbulletin
/ Wednesday , December 25 2024
Northwave Cyber Security has found a sophisticated backdoor, LITTLELAMB.WOOLTEA, targeting Palo Alto Networks firewalls. Northwave researcher claimed the backdoor was...
Read More
By infosecbulletin
/ Tuesday , December 24 2024
A newly discovered vulnerability called "G-Door" enables malicious actors to bypass Microsoft 365 security by exploiting unmanaged Google Docs accounts....
Read More
By infosecbulletin
/ Tuesday , December 24 2024
Adobe has issued urgent security updates for ColdFusion versions 2023 and 2021 to fix a critical vulnerability (CVE-2024-53961). This flaw...
Read More
By infosecbulletin
/ Monday , December 23 2024
Splunk, a unified security and observability platform turn its focuses on Bangladeshi market. On Monday (23 December) Splunk's local partner...
Read More
By infosecbulletin
/ Sunday , December 22 2024
A major security flaw in Craft CMS, a popular PHP content management system, has been found, enabling unauthenticated remote code...
Read More
By infosecbulletin
/ Sunday , December 22 2024
Mastercard has completed its acquisition of Recorded Future, an AI-based threat intelligence provider. Mastercard has acquired the company for $2.65...
Read More
“A denial-of-service vulnerability in the DNS Security feature of Palo Alto Networks PAN-OS software allows an unauthenticated attacker to send a malicious packet through the data plane of the firewall that reboots the firewall,” the company said in a Friday advisory.
“Repeated attempts to trigger this condition will cause the firewall to enter maintenance mode.”
Palo Alto Networks said it discovered the flaw in production use, and that it’s aware of customers “experiencing this denial-of-service (DoS) when their firewall blocks malicious DNS packets that trigger this issue.”
The activity’s scope is currently unclear. Hacker News has contacted Palo Alto Networks for comment and will update the story if they respond.
Firewalls with DNS Security logging enabled are affected by CVE-2024-3393. The flaw’s severity is reduced to a CVSS score of 7.1 when access is limited to authenticated users through Prisma Access.
The fixes have also been extended to other commonly deployed maintenance releases –
As workarounds and mitigations for unmanaged firewalls or those managed by Panorama, customers have the option of setting Log Severity to “none” for all configured DNS Security categories for each Anti-Spyware profile by navigating to Objects > Security Profiles > Anti-spyware > (select a profile) > DNS Policies > DNS Security.
Users can disable DNS Security logging on firewalls managed by Strata Cloud Manager (SCM) either individually or for all devices by opening a support case. For Prisma Access tenants, it’s recommended to open a support case to disable logging until an upgrade is performed.