CVE-2024-9468
Severity CVSS v4.0:
HIGH
Type:
CWE-787
Out-of-bounds Write
Publication date:
09/10/2024
Last modified:
01/12/2025
Description
A memory corruption vulnerability in Palo Alto Networks PAN-OS software allows an unauthenticated attacker to crash PAN-OS due to a crafted packet through the data plane, resulting in a denial of service (DoS) condition. Repeated attempts to trigger this condition will result in PAN-OS entering maintenance mode.
Impact
Base Score 4.0
8.20
Severity 4.0
HIGH
Base Score 3.x
7.50
Severity 3.x
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:paloaltonetworks:pan-os:*:*:*:*:*:*:*:* | 10.2.0 (including) | 10.2.4 (excluding) |
| cpe:2.3:o:paloaltonetworks:pan-os:*:*:*:*:*:*:*:* | 10.2.5 (including) | 10.2.7 (excluding) |
| cpe:2.3:o:paloaltonetworks:pan-os:*:*:*:*:*:*:*:* | 11.0.0 (including) | 11.0.4 (excluding) |
| cpe:2.3:o:paloaltonetworks:pan-os:*:*:*:*:*:*:*:* | 11.0.5 (including) | 11.0.6 (excluding) |
| cpe:2.3:o:paloaltonetworks:pan-os:*:*:*:*:*:*:*:* | 11.1.0 (including) | 11.1.3 (excluding) |
| cpe:2.3:o:paloaltonetworks:pan-os:10.2.4:-:*:*:*:*:*:* | ||
| cpe:2.3:o:paloaltonetworks:pan-os:10.2.4:h10:*:*:*:*:*:* | ||
| cpe:2.3:o:paloaltonetworks:pan-os:10.2.4:h16:*:*:*:*:*:* | ||
| cpe:2.3:o:paloaltonetworks:pan-os:10.2.4:h2:*:*:*:*:*:* | ||
| cpe:2.3:o:paloaltonetworks:pan-os:10.2.4:h3:*:*:*:*:*:* | ||
| cpe:2.3:o:paloaltonetworks:pan-os:10.2.4:h4:*:*:*:*:*:* | ||
| cpe:2.3:o:paloaltonetworks:pan-os:10.2.7:-:*:*:*:*:*:* | ||
| cpe:2.3:o:paloaltonetworks:pan-os:10.2.7:h1:*:*:*:*:*:* | ||
| cpe:2.3:o:paloaltonetworks:pan-os:10.2.7:h10:*:*:*:*:*:* | ||
| cpe:2.3:o:paloaltonetworks:pan-os:10.2.7:h11:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



