Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-3386


An incorrect string comparison vulnerability in Palo Alto Networks PAN-OS software prevents Predefined Decryption Exclusions from functioning as intended. This can cause traffic destined for domains that are not specified in Predefined Decryption Exclusions to be unintentionally excluded from decryption.


Published

2024-04-10T17:15:57.593

Last Modified

2025-01-24T15:58:52.233

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 5.3 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-436
  • Type: Primary
    CWE-436

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System paloaltonetworks pan-os < 9.0.16 Yes
Operating System paloaltonetworks pan-os < 9.1.17 Yes
Operating System paloaltonetworks pan-os < 10.0.13 Yes
Operating System paloaltonetworks pan-os ≤ 10.1.8 Yes
Operating System paloaltonetworks pan-os < 10.2.4 Yes
Operating System paloaltonetworks pan-os < 11.0.1 Yes
Operating System paloaltonetworks pan-os 9.0.17 Yes
Operating System paloaltonetworks pan-os 9.0.17 Yes
Operating System paloaltonetworks pan-os 10.1.9 Yes
Operating System paloaltonetworks pan-os 10.1.9 Yes
Operating System paloaltonetworks pan-os 10.2.4 Yes
Operating System paloaltonetworks pan-os 11.0.1 Yes

References