Unauthenticated Null Pointer Dereference Vulnerability Leads to DoS Condition and Maintenance Mode
CVE-2024-2551

7.5HIGH

Key Information:

Vendor
CVE Published:
14 November 2024

Summary

A null pointer dereference vulnerability in Palo Alto Networks PAN-OS can allow unauthenticated attackers to disrupt core system services on the firewall. By sending specially crafted packets through the data plane, attackers can trigger a denial of service (DoS) condition. If exploited repeatedly, this vulnerability may cause the firewall to enter maintenance mode, leading to severe system disruptions. It is essential for organizations using affected versions of PAN-OS to apply timely updates and mitigate risks associated with this vulnerability.

Affected Version(s)

PAN-OS 11.0.0 < 11.0.5

PAN-OS 10.2.0 < 10.2.4-h6

PAN-OS 10.1.0 < 10.1.14

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

a customer
.