CISA Known Exploited Vulnerability (KEV)
Palo Alto Networks PAN-OS Malicious DNS Packet Vulnerability
December 30, 2024
January 20, 2025
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Description
A Denial of Service vulnerability in the DNS Security feature of Palo Alto Networks PAN-OS software allows an unauthenticated attacker to send a malicious packet through the data plane of the firewall that reboots the firewall. Repeated attempts to trigger this condition will cause the firewall to enter maintenance mode.
Weakness Enumeration
CWE-ID | CWE Name |
---|---|
CWE-754 |
Improper Check for Unusual or Exceptional Conditions |