Zultys Security Advisory Notice - SAN25-001 Rev 1.0

Vulnerability in Palo Alto PAN-OS DNS Security (CVE-2024-3393)

Severity: No Impact

Published: 2025-01-07

Updated: 2025-01-07

Revision: 1.0

Evaluated Products

Zultys Cloud Services

Impacted Products

None

Affected Releases

Not applicable

Impacted 3rd Party Products

Not applicable

Introduction

On December 27, 2024 details of a Denial of Service vulnerability in the DNS Security feature of Palo Alto Networks PAN-OS software was published in the National Vulnerability Database under CVE-2024-3393. The vulnerability allows an unauthenticated attacker to send a malicious packet through the data plane of the Palo Alto firewall that results in the firewall rebooting and eventually forcing it to enter maintenance mode.

Description

Zultys Cloud Services systems hosted in Zultys data centers are not impacted.

Customers utilizing a Palo Alto firewall to protect deployed MX systems should review the information available from Palo Alto Networks and ensure the firewall is appropriately updated and configured to protect against CVE-2024-3393.

Contact

If additional information is required contact support@zultys.com or your Authorized Zultys Channel Partner.