Palo Alto Networks released fixes for CVE-2024-3393, a high-severity denial-of-service flaw in the PAN-OS DNS Security component that can be exploited remotely and without authentication using specially crafted DNS packets. Successful exploitation can force affected firewalls to reboot and, if repeated, push them into maintenance mode, leaving devices unavailable; CSIRT.SK reported the vulnerability is being actively exploited in the wild.
Affected products include multiple PAN-OS 10.1, 10.2, 11.1, and 11.2 releases, as well as Prisma Access deployments running vulnerable PAN-OS versions. Exploitation requires DNS Security Logging to be enabled along with either a DNS Security License or Advanced DNS Security License. Palo Alto urged organizations to upgrade immediately to fixed releases and to apply configuration-based mitigations where patching cannot be completed right away.

See which actors are running it and whether you're in range.
2 events from the most recent confirmed update back to the earliest known activity.
CSIRT.SK reported that CVE-2024-3393 is being actively exploited in the wild. The notice said affected PAN-OS versions include multiple 10.1, 10.2, 11.1, and 11.2 releases, as well as Prisma Access deployments using vulnerable PAN-OS versions, when DNS Security Logging and the relevant DNS Security license are enabled.
Palo Alto Networks released security updates for CVE-2024-3393, a high-severity PAN-OS denial-of-service flaw in the DNS Security component that can be triggered remotely without authentication using specially crafted DNS packets. The issue can cause affected firewalls to reboot and, if repeatedly exploited, enter maintenance mode and become unavailable.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
2 references tracked. Mallory keeps watching after this page renders.
csirt.sk
Open sourcesecurity.paloaltonetworks.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.