Impact
Multiple vulnerabilities in Palo Alto Networks PAN‑OS allow an unauthenticated attacker with network access to cause a denial of service by sending specially crafted packets to a dataplane interface. Repeated exploitation can push the firewall into maintenance mode, rendering it unavailable to legitimate traffic and potentially disrupting critical network services. The CVSS score of 4.6 indicates moderate severity; however, the effect on firewall availability is particularly disruptive for continuous‑operation environments.
Affected Systems
The vulnerabilities affect a range of PAN‑OS versions from 10.2.x through 12.1.x and various releases of Cloud NGFW and Prisma Access. Affected product families include Palo Alto Networks PAN‑OS and Prisma Access; Panorama is explicitly not impacted. The detailed version list in the vendor solution guide enumerates specific fix versions for each product line.
Risk and Exploitability
The CVSS score of 4.6 classifies this DoS as moderate severity, yet the event disrupts firewall availability which can impede critical services. The EPSS score below 1 % indicates a very low likelihood of exploitation, but the vulnerability can be triggered from any device with network reach to a dataplane interface, implying a simple network‑level attack. No known exploits are listed in the CISA KEV catalog, so the risk profile relies largely on the potential for an internal or opportunistic attacker to generate the crafted traffic. Organizations should prioritize applying the vendor‑recommended patch to eliminate the DoS risk.
OpenCVE Enrichment