CVE-2024-3387
Severity CVSS v4.0:
Pending analysis
Type:
CWE-326
Inadequate Encryption Strength
Publication date:
10/04/2024
Last modified:
30/01/2026
Description
A weak (low bit strength) device certificate in Palo Alto Networks Panorama software enables an attacker to perform a meddler-in-the-middle (MitM) attack to capture encrypted traffic between the Panorama management server and the firewalls it manages. With sufficient computing resources, the attacker could break encrypted communication and expose sensitive information that is shared between the management server and the firewalls.
Impact
Base Score 3.x
5.30
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:paloaltonetworks:pan-os:*:*:*:*:*:*:*:* | 10.1.0 (including) | 10.1.12 (excluding) |
| cpe:2.3:o:paloaltonetworks:pan-os:*:*:*:*:*:*:*:* | 10.2.0 (including) | 10.2.7 (excluding) |
| cpe:2.3:o:paloaltonetworks:pan-os:*:*:*:*:*:*:*:* | 11.0.0 (including) | 11.0.4 (excluding) |
| cpe:2.3:o:paloaltonetworks:pan-os:10.2.7:h1:*:*:*:*:*:* | ||
| cpe:2.3:o:paloaltonetworks:pan-os:10.2.7:h2:*:*:*:*:*:* | ||
| cpe:2.3:o:paloaltonetworks:pan-os:10.2.7:h3:*:*:*:*:*:* | ||
| cpe:2.3:o:paloaltonetworks:pan-os:10.2.7:h4:*:*:*:*:*:* | ||
| cpe:2.3:o:paloaltonetworks:pan-os:10.2.7:h5:*:*:*:*:*:* | ||
| cpe:2.3:o:paloaltonetworks:pan-os:10.2.7:h6:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



