CVE-2021-3031
PAN-OS vulnerability analysis and mitigation

Overview

CVE-2021-3031, also known as Etherleak, is a vulnerability discovered in Palo Alto Networks' PAN-OS firewall systems. The vulnerability was disclosed on January 13, 2021, affecting multiple firewall models including PA-200, PA-220, PA-500, PA-800, PA-2000 Series, PA-3000 Series, PA-3200 Series, PA-5200 Series, and PA-7000 Series. The issue impacts PAN-OS versions 8.1 (earlier than 8.1.18), 9.0 (earlier than 9.0.12), and 9.1 (earlier than 9.1.5) (Palo Alto Advisory).

Technical details

The vulnerability stems from padding bytes in Ethernet packets not being cleared before data frame creation on affected firewall systems. This results in information leakage where random data from the firewall's memory is exposed in Ethernet packets. The vulnerability has been assigned a CVSS v3.1 Base Score of 4.3 (MEDIUM) with the following metrics: Attack Vector: ADJACENT_NETWORK, Attack Complexity: LOW, Privileges Required: NONE, User Interaction: NONE, Scope: UNCHANGED, Confidentiality Impact: LOW, Integrity Impact: NONE, Availability Impact: NONE. The vulnerability is classified as CWE-200 (Information Exposure) (Palo Alto Advisory).

Impact

The vulnerability allows an attacker on the same Ethernet subnet as the PAN-OS firewall to collect potentially sensitive information from the leaked memory data in Ethernet packets. While the impact is limited to information disclosure, the leaked data could potentially contain sensitive information from the firewall's memory (Palo Alto Advisory).

Exploitability

According to Palo Alto Networks, there was no known malicious exploitation of this vulnerability at the time of disclosure. The vulnerability requires the attacker to be on the same Ethernet subnet as the affected firewall to collect the leaked information (Palo Alto Advisory).

Mitigation and workarounds

The vulnerability has been fixed in PAN-OS versions 8.1.18, 9.0.12, 9.1.5, and all later PAN-OS versions. While there is no direct workaround to prevent the information leak in the Ethernet packets, Palo Alto Networks recommends restricting access to the networks as a mitigation measure to reduce the risk (Palo Alto Advisory).

Additional resources


SourceThis report was generated using AI

Related PAN-OS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-0287MEDIUM6.6
  • PAN-OS logoPAN-OS
  • cpe:2.3:o:paloaltonetworks:pan-os
NoYesJul 09, 2026
CVE-2026-0286MEDIUM6
  • PAN-OS logoPAN-OS
  • cpe:2.3:o:paloaltonetworks:pan-os
NoYesJul 09, 2026
CVE-2026-0285MEDIUM4.7
  • PAN-OS logoPAN-OS
  • cpe:2.3:o:paloaltonetworks:pan-os
NoYesJul 09, 2026
CVE-2026-0284MEDIUM4.7
  • PAN-OS logoPAN-OS
  • cpe:2.3:o:paloaltonetworks:pan-os
NoYesJul 09, 2026
CVE-2026-0283MEDIUM4.5
  • PAN-OS logoPAN-OS
  • cpe:2.3:o:paloaltonetworks:pan-os
NoYesJul 09, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management