H-ISAC TLP White Threat Bulletin: Palo Alto Networks Reports on the Exploitation of a New Flaw CVE-2024-3393

On December 27, 2024, Palo Alto Networks disclosed a high-severity vulnerability, tracked as CVE-2024-3393, in its PAN-OS software that affects the DNS Security feature. According to the advisory, the flaw has already been exploited.

This flaw allows unauthenticated attackers to send malicious DNS packets, potentially causing Denial of Service (DoS) disruptions and forcing firewalls into maintenance mode. The company said it has reports of some of its customers already experiencing DoS when the firewall attempts to block the malicious DNS packets. 

View the detailed bulletin below.

For help with Cybersecurity and Risk Advisory Services exclusively for AHA members, contact:

John Riggi

National Advisor for Cybersecurity and Risk, AHA

jriggi@aha.org

(O) +1 202 626 2272