02 Records
FEED: ACQUIRING
01 RecordSTATE: PUBLISHED
02 Description
CNA: palo_altoPAN-OS: Firewall Denial of Service (DoS) in DNS Security Using a Specially Crafted Packet
03 Exploitation and scoring
SRC: CISA, FIRST, NVD, RED HAT- Exploitation
- Exploited in the wild. Listed in the CISA Known Exploited Vulnerabilities catalog on 2024-12-30. Federal remediation due 2025-01-20.
- SSVC decision
- ExploitationactiveCISA reports credible evidence of active exploitation.
- AutomatableyesAn attacker can reliably automate reconnaissance through exploitation, so this scales.
- Technical ImpactpartialSuccessful exploitation gives limited control of the vulnerable component.
CISA publishes the decision points, not a final SSVC decision. The decision also depends on mission and well-being impact, which is a property of your deployment rather than of the vulnerability.- EPSS probability
- 28.62% probability of exploitation activity in the next 30 days.
- EPSS percentile
- Ranks above 98.0% of scored records. A rank, not a probability.
- NVD base score
- 8.7 (CVSS v4.0), scored by the NVD independently of the CNA.
- NVD CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:C/RE:M/U:Amber
- NVD analysis status
- Analyzed. NVD last modified this record on 2026-06-17.
- Red Hat severity
- No Red Hat rating. Red Hat rates the CVEs that affect its products.
Exploit-prediction scores from FIRST. Independent scoring and analysis status from the NVD. Vendor severity from Red Hat. Exploitation assessment and catalog membership from CISA.
SCHEMA: 5.1
- Published
- 2024-12-27 09:44Z1 YR AGO
- Last updated
- 2025-10-21 22:55Z10 MO AGO
- Reserved
- 2024-04-05
- Assigning CNA
- palo_alto
- Record state
- PUBLISHED
- Severity
- High (CVSS 8.7)
- CNA CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L/AU:N/R:U/V:C/RE:M/U:Amber
- Weaknesses
- CWE-754Improper Check for Unusual or Exceptional ConditionsClass
- Data version
- 5.1
- Document digest
- a1b5e012e79e1895db8466c982f33006a5ec7988abf92a095cf12618da7f2864
05 Affected products
PAIRS: 2VendorProductVersionsPlatforms
Palo Alto NetworksPAN-OS11.2.0 to < 11.2.3, 11.1.0 to < 11.1.2-h16, 10.2.8 to < 10.2.8-h19, 10.1.14 to < 10.1.14-h8Prisma Access SRC: CNA
This issue is fixed in PAN-OS 10.1.14-h8, PAN-OS 10.2.10-h12, PAN-OS 11.1.5, PAN-OS 11.2.3, and all later PAN-OS versions.
Note: PAN-OS 11.0 reached the end of life (EOL) on November 17, 2024, so we do not intend to provide a fix for this release.
Prisma Access customers using DNS Security with affected PAN-OS versions should apply one of the workarounds provided below. We will perform upgrades in two phases for impacted customers on the weekends of January 3rd and January 10th. You can request an expedited Prisma Access upgrade to the latest PAN-OS version by opening a support case https://support.paloaltonetworks.com/Support/Index .
In addition, to provide the most seamless upgrade path for our customers, we are making fixes available for other TAC-preferred and commonly deployed maintenance releases.
Additional PAN-OS 11.1 fixes:
* 11.1.2-h16
* 11.1.3-h13
* 11.1.4-h7
* 11.1.5
Additional PAN-OS 10.2 fixes:
* 10.2.8-h19
* 10.2.9-h19
* 10.2.10-h12
* 10.2.11-h10
* 10.2.12-h4
* 10.2.13-h2
* 10.2.14
Additional PAN-OS 10.1 fixes:
* 10.1.14-h8
* 10.1.15
Additional PAN-OS fixes only applicable to Prisma Access:
* 10.2.9-h19
* 10.2.10-h12