A null pointer dereference vulnerability in Palo Alto Networks PAN-OS software enables an unauthenticated attacker to stop a core system service on the firewall by sending a crafted packet through the data plane that causes a denial of service (DoS) condition. Repeated attempts to trigger this condition result in the firewall entering maintenance mode.
2024-11-14T10:15:04.547
2025-01-24T16:03:41.910
Analyzed
CVSSv3.1: 7.5 (HIGH)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | paloaltonetworks | pan-os | < 10.1.14 | Yes |
Operating System | paloaltonetworks | pan-os | < 10.2.4 | Yes |
Operating System | paloaltonetworks | pan-os | < 11.0.5 | Yes |
Operating System | paloaltonetworks | pan-os | 10.2.4 | Yes |
Operating System | paloaltonetworks | pan-os | 10.2.4 | Yes |
Operating System | paloaltonetworks | pan-os | 10.2.4 | Yes |
Operating System | paloaltonetworks | pan-os | 10.2.4 | Yes |