Impact
Multiple denial‑of‑service vulnerabilities in Palo Alto Networks PAN‑OS allow an unauthenticated attacker with network access to trigger a service outage by sending specially crafted network traffic. The weakness is identified as CWE‑754, indicating improper handling of system allocation or resource exhaustion conditions that can be abused to crash or stall the firewall software. No elevation of privilege or data theft is possible; the effect is limited to availability disruption of the affected device.
Affected Systems
Vendors: Palo Alto Networks. Products: PAN‑OS, Cloud NGFW, and Prisma Access. Affected PAN‑OS releases include 12.1.5 through 12.1.6, 12.1.2 through 12.1.4‑h*, 11.2.11 or later, 11.2.8 through 11.2.10‑h*, 11.2.5 through 11.2.7‑h*, 11.2.0 through 11.2.4‑h*, 11.1.14 or later, 11.1.11 through 11.1.13‑h*, 11.1.8 through 11.1.10‑h*, 11.1.7 through 11.1.7‑h*, 11.1.5 through 11.1.6‑h*, 10.2.17 through 10.2.18‑h*, 10.2.14 through 10.2.16‑h*, 10.2.11 through 10.2.13‑h*, 10.2.8 through 10.2.10‑h*, and 10.2.0 through 10.2.7‑h*. Cloud NGFW is not impacted and no action is required for that platform.
Risk and Exploitability
The CVSS score of 6.6 signals a moderate severity, primarily reflecting availability impact. Because the EPSS score is not available and the vulnerability is not listed in CISA KEV, there is no currently documented exploitation in the wild. Exploitation requires only network connectivity to the vulnerable PAN‑OS device and no credentials; thus an unauthenticated, remote attacker can trigger the DoS by sending crafted packets. The risk is centered on potential downtime and degraded network service rather than data compromise.
OpenCVE Enrichment