Impact
An IPv6 packet processing defect in PAN‑OS’s dataplane allows an unauthenticated attacker to craft packets that bypass the firewall policy engine. The flaw is a buffer size calculation error (CWE‑131) that corrupts the integrity of policy enforcement, permitting traffic that should be blocked to reach protected services without any credentials or administrative access.
Affected Systems
Affected PAN‑OS firmware versions that preceded the fixed releases must be upgraded. 10.2.0 through 10.2.18‑h* should be updated to 10.2.18‑h8 or later; 11.1.0 through 11.1.6‑h* to 11.1.16 or later; 11.2.0 through 11.2.7‑h* to 11.2.13 or later; 12.1.0 through 12.1.1 to 12.1.8 or later; 12.1.2 through 12.1.4‑h* to 12.1.4‑h8 or 12.1.8 or later; 12.1.5 through 12.1.7‑h* to 12.1.7‑h2 or 12.1.8 or later. Prisma Access versions 10.2.0 through 10.2.10‑h* should be upgraded to 10.2.10‑h39 or later, and 11.2.0 through 11.2.7‑h* to 11.2.7‑h18 or later. Cloud NGFW and Panorama are not impacted.
Risk and Exploitability
The CVSS score of 1.7 classifies the vulnerability as low severity. The EPSS score is below 1%, indicating a very small likelihood of exploitation in the wild, and the flaw is not currently identified in the CISA KEV catalog. The likely attack vector is from an external network where an attacker can send specially crafted IPv6 packets that the device processes without proper policy checks. This bypass does not require user interaction or elevated privileges; it can be performed remotely by flooding the device with malicious packets, leading to policy circumvention and potential exposure of services that should be blocked. The impact is limited to integrity of policy enforcement, but because the bypass allows traffic that should be blocked, it can compromise confidentiality of protected services or affect availability if the device is overwhelmed with unwanted traffic.
OpenCVE Enrichment