Unauthenticated Null Pointer Dereference Vulnerability Leads to DoS Condition and Maintenance Mode
CVE-2024-2551
7.5HIGH
Key Information:
- Vendor
- Palo Alto Networks
- Vendor
- CVE Published:
- 14 November 2024
Summary
A null pointer dereference vulnerability in Palo Alto Networks PAN-OS can allow unauthenticated attackers to disrupt core system services on the firewall. By sending specially crafted packets through the data plane, attackers can trigger a denial of service (DoS) condition. If exploited repeatedly, this vulnerability may cause the firewall to enter maintenance mode, leading to severe system disruptions. It is essential for organizations using affected versions of PAN-OS to apply timely updates and mitigate risks associated with this vulnerability.
Affected Version(s)
PAN-OS 11.0.0 < 11.0.5
PAN-OS 10.2.0 < 10.2.4-h6
PAN-OS 10.1.0 < 10.1.14
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
a customer