Answer in brief
CVE-2024-3393 records a High severity vulnerability in PAN-OS: Firewall Denial of Service (DoS) in DNS Security Using a Specially Crafted Packet. The current sources mark it as known exploited. The current feed maps Palo Alto Networks/PAN-OS (generic), Palo Alto Networks/PAN-OS (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. Known-exploitation status makes exposure review time-sensitive. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Palo Alto Networks/PAN-OS (generic), Palo Alto Networks/PAN-OS (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Palo Alto Networks/PAN-OSgeneric | >=11.2.0 <11.2.3 || >=11.1.0 <11.1.2-h16 || >=10.2.8 <10.2.8-h19 || >=10.1.14 <10.1.14-h8 | 11.2.3, 11.1.2-h16, 10.2.8-h19, 10.1.14-h8 |
| Palo Alto Networks/PAN-OSgeneric | >=11.2.0 <11.2.3 | 11.2.3 |
Published upstream
Dec 27, 2024
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Oct 21, 2025
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
May 24, 2026
Added to CISA KEV
Dec 30, 2024
Evidence: source:kev:kev:kev:recordA Denial of Service vulnerability in the DNS Security feature of Palo Alto Networks PAN-OS software allows an unauthenticated attacker to send a malicious packet through the data plane of the firewall that reboots the firewall. Repeated attempts to trigger this condition will cause the firewall to enter maintenance mode.
Quoted source text, attributed separately from HOL analysis.
Answer in brief
CVE-2024-3393 records a High severity vulnerability in PAN-OS: Firewall Denial of Service (DoS) in DNS Security Using a Specially Crafted Packet. The current sources mark it as known exploited. The current feed maps Palo Alto Networks/PAN-OS (generic), Palo Alto Networks/PAN-OS (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. Known-exploitation status makes exposure review time-sensitive. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Palo Alto Networks/PAN-OS (generic), Palo Alto Networks/PAN-OS (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Palo Alto Networks/PAN-OSgeneric | >=11.2.0 <11.2.3 || >=11.1.0 <11.1.2-h16 || >=10.2.8 <10.2.8-h19 || >=10.1.14 <10.1.14-h8 | 11.2.3, 11.1.2-h16, 10.2.8-h19, 10.1.14-h8 |
| Palo Alto Networks/PAN-OSgeneric | >=11.2.0 <11.2.3 | 11.2.3 |
Published upstream
Dec 27, 2024
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Oct 21, 2025
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
May 24, 2026
Added to CISA KEV
Dec 30, 2024
Evidence: source:kev:kev:kev:recordA Denial of Service vulnerability in the DNS Security feature of Palo Alto Networks PAN-OS software allows an unauthenticated attacker to send a malicious packet through the data plane of the firewall that reboots the firewall. Repeated attempts to trigger this condition will cause the firewall to enter maintenance mode.
Quoted source text, attributed separately from HOL analysis.