CVE-2024-3385
PAN-OS vulnerability analysis and mitigation

Overview

A packet processing mechanism vulnerability (CVE-2024-3385) was discovered in Palo Alto Networks PAN-OS software that affects PA-5400 and PA-7000 Series hardware firewalls. The vulnerability was disclosed on April 10, 2024, and enables remote attackers to reboot hardware-based firewalls when GTP Security is disabled (Palo Advisory, NVD).

Technical details

The vulnerability is classified with a CVSS v3.1 base score of 7.5 (HIGH) with the vector string CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H. It is categorized under CWE-476 (NULL Pointer Dereference) and CWE-20 (Improper Input Validation). The issue specifically affects PAN-OS configurations with GTP Security disabled and does not impact VM-Series firewalls, CN-Series firewalls, Cloud NGFWs, or Prisma Access (Palo Advisory).

Impact

When exploited, the vulnerability allows attackers to repeatedly cause firewall reboots, eventually forcing the system into maintenance mode. This condition requires manual intervention to restore firewall operations, potentially leading to significant service disruption. The vulnerability primarily affects availability with no impact on confidentiality or integrity (Palo Advisory).

Exploitability

The vulnerability was discovered through normal production usage by two customers, and Palo Alto Networks has stated they are not aware of any malicious exploitation of this issue in the wild. The attack vector is network-based, requires low attack complexity, and no privileges or user interaction (Palo Advisory).

Mitigation and workarounds

The vulnerability has been patched in PAN-OS versions 9.0.17-h4, 9.1.17, 10.1.12, 10.2.8, 11.0.3, and all later versions. For customers with a Threat Prevention subscription, enabling Threat ID 94993 (introduced in Applications and Threats content version 8832) can block attacks targeting this vulnerability (Palo Advisory).

Additional resources


SourceThis report was generated using AI

Related PAN-OS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-0287MEDIUM6.6
  • PAN-OS logoPAN-OS
  • cpe:2.3:o:paloaltonetworks:pan-os
NoYesJul 09, 2026
CVE-2026-0286MEDIUM6
  • PAN-OS logoPAN-OS
  • cpe:2.3:o:paloaltonetworks:pan-os
NoYesJul 09, 2026
CVE-2026-0285MEDIUM4.7
  • PAN-OS logoPAN-OS
  • cpe:2.3:o:paloaltonetworks:pan-os
NoYesJul 09, 2026
CVE-2026-0284MEDIUM4.7
  • PAN-OS logoPAN-OS
  • cpe:2.3:o:paloaltonetworks:pan-os
NoYesJul 09, 2026
CVE-2026-0283MEDIUM4.5
  • PAN-OS logoPAN-OS
  • cpe:2.3:o:paloaltonetworks:pan-os
NoYesJul 09, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management