Evidence dossier

CVE-2024-3393

PAN-OS: Firewall Denial of Service (DoS) in DNS Security Using a Specially Crafted Packet

Exploited in the wild (CISA KEV since Dec 30, 2024). palo_alto reports CVSS 4.0 7.1. Severity assessments differ within at least one CVSS version. EPSS estimates 28.6% exploit likelihood as of Aug 27, 2026.

72.079.0Priority evidence range
Evidence current through Aug 27, 2026, 6:09 PM UTC

As of Aug 27, 2026

Normalized restatement

A Denial of Service vulnerability in the DNS Security feature of Palo Alto Networks PAN-OS software allows an unauthenticated attacker to send a malicious packet through the data plane of the firewall that reboots the firewall. Repeated attempts to trigger this condition will cause the firewall to enter maintenance mode.

State
PUBLISHED
Published
Dec 27, 2024
Updated
Oct 21, 2025
Evidence coverage
86%

Evidence chronology

What was known when

Download this view's receipt →
  1. Source dateSource date omittedFirst observed by CASCA
    CISA-ADP

    Record text: CISA ADP Vulnrichment

    Inspect raw assertion
    Field
    container
    Value
    CISA ADP Vulnrichment
    Original evidence ↗
  2. Source dateSource date omittedFirst observed by CASCA
    palo_alto

    Record text: PAN-OS: Firewall Denial of Service (DoS) in DNS Security Using a Specially Crafted Packet

    Inspect raw assertion
    Field
    container
    Value
    PAN-OS: Firewall Denial of Service (DoS) in DNS Security Using a Specially Crafted Packet
    Original evidence ↗
  3. Source dateFirst observed by CASCA
    CISA KEV

    Exploitation cataloged: Palo Alto Networks PAN-OS Malicious DNS Packet Vulnerability

    Inspect raw assertion
    Field
    observed_exploitation
    Value
    Palo Alto Networks PAN-OS Malicious DNS Packet Vulnerability
    Original evidence ↗
  4. Source dateFirst observed by CASCA
    FIRST EPSS

    EPSS score: 28.62% probability · 97.99th percentile

    Inspect raw assertion
    Field
    model_probability
    Value
    Probability 0.286170000000; percentile 0.979930000000
    Original evidence ↗

Assessments differ

NVD7.5CVSS 3.1 · source date omitted
psirt@paloaltonetworks.com8.7CVSS 4.0 · source date omitted

Values are shown separately by source and CVSS version.

ExploitationCatalog member

CISA KEV · catalog date Dec 30, 2024 · first observed Jul 19, 2026

Exploit likelihood28.62%

FIRST EPSS · score date Aug 27, 2026 · 98th percentile · first observed Aug 27, 2026

SeverityAssessments differ

palo_alto · CVSS 4.0 · first observed Jul 19, 2026 · values shown separately below

Evidence detail

Source limits and decisions

Why each evidence state has this value

Outside this view’s verified evidence

Reason detail begins outside this selected snapshot; the state remains source-bound.

Source comparison

Who said what

CISA-ADPIndependent enrichment
Record text

CISA ADP Vulnrichment

Inspect raw assertion
Field
container
Value
CISA ADP Vulnrichment
Source dateSource date omittedFirst observed by CASCAOriginal evidence ↗
palo_altoOriginal assertion
Record text

PAN-OS: Firewall Denial of Service (DoS) in DNS Security Using a Specially Crafted Packet

Inspect raw assertion
Field
container
Value
PAN-OS: Firewall Denial of Service (DoS) in DNS Security Using a Specially Crafted Packet
Source dateSource date omittedFirst observed by CASCAOriginal evidence ↗
CISA KEVOriginal assertion
Exploitation cataloged

Palo Alto Networks PAN-OS Malicious DNS Packet Vulnerability

Inspect raw assertion
Field
observed_exploitation
Value
Palo Alto Networks PAN-OS Malicious DNS Packet Vulnerability
Source dateFirst observed by CASCAOriginal evidence ↗
FIRST EPSSOriginal assertion
EPSS score

28.62% probability · 97.99th percentile

Inspect raw assertion
Field
model_probability
Value
Probability 0.286170000000; percentile 0.979930000000
Source dateFirst observed by CASCAOriginal evidence ↗

Applicability

Cited product scope

Trace impact →
84Underlying assertions
2Canonical products
60Target assertions
24Constraint assertions

Grouped from 3 configuration nodes in this exact snapshot. Visual grouping is navigational; asset exposure and root cause require cited evidence.

Identity source boundaries
  • Cpe dictionary1,775,266 records · observed through 2026-07-21T06:45:29.809Z27d65b0f-b718-4b4f-bb79-c47c68d09dfa
  • Cpe match643,502 records · observed through 2026-07-21T08:13:17.697Z955dae73-7302-438b-aee1-058d7cc5d48e

6 scope groups

palo_alto · source assertedPalo Alto NetworksCloud NGFWDirect source scope
Unaffected: All
Source-reported scope

Canonical linkage remains open; the cited source assertion is retained below.

Inspect raw assertion[{"status": "unaffected", "version": "All"}]
palo_alto · source assertedPalo Alto NetworksPAN-OSDirect source scope
Affected: 11.2.0 to before 11.2.3 (custom comparison)Affected: 11.1.0 to before 11.1.2-h16 (custom comparison)Affected: 10.2.8 to before 10.2.8-h19 (custom comparison)Affected: 10.1.14 to before 10.1.14-h8 (custom comparison)
Source-reported scope

Canonical linkage remains open; the cited source assertion is retained below.

Inspect raw assertion[{"status": "affected", "version": "11.2.0", "lessThan": "11.2.3", "versionType": "custom"}, {"status": "affected", "version": "11.1.0", "lessThan": "11.1.2-h16", "versionType": "custom"}, {"status": "affected", "version": "10.2.8", "lessThan": "10.2.8-h19", "versionType": "custom"}, {"status": "affected", "version": "10.1.14", "lessThan": "10.1.14-h8", "versionType": "custom"}]
palo_alto · source assertedPalo Alto NetworksPAN-OSDirect source scope
Unaffected: 10.2.0 to before 10.2.8 (custom comparison)Affected: 11.2.0 to before 11.2.3 (custom comparison)
Source-reported scope

Canonical linkage remains open; the cited source assertion is retained below.

Inspect raw assertion[{"status": "unaffected", "version": "10.2.0", "lessThan": "10.2.8", "versionType": "custom"}, {"status": "affected", "version": "11.2.0", "lessThan": "11.2.3", "versionType": "custom"}]
NVD CPE · OPERATING SYSTEMpaloaltonetworkspan-osVulnerable target · 59 assertions
Any version (unconstrained) (>= 11.1.0, <= 11.1.1); Any version (unconstrained) (>= 11.2.0, < 11.2.3); Version 10.1.14; Version 10.2.10; Version 10.2.11; Version 10.2.12; Version 10.2.13; Version 10.2.8; Version 10.2.9; Version 11.1.2; Version 11.1.3; Version 11.1.4Canonical identity product-612afb736440531327cd224402d663e14e2a3f421cc65267d8acade0f3b99df7Linked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:o:paloaltonetworks:pan-os:11.1.3:h4:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 54
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    502bf06e-5b51-41f7-9a88-26051675fe0c
  2. cpe:2.3:o:paloaltonetworks:pan-os:10.2.8:h15:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 9
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    d1ecd1dc-5a05-4e4f-97f5-136ce777fab3
  3. cpe:2.3:o:paloaltonetworks:pan-os:10.2.13:h1:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 40
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    f1fc63b8-b8d9-4ec1-85ca-2e12b38acd3e
  4. cpe:2.3:o:paloaltonetworks:pan-os:11.1.3:-:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 49
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    d828f283-5ce8-49ba-bfef-92471c2adeae
  5. cpe:2.3:o:paloaltonetworks:pan-os:10.2.12:-:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 35
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    3d33a0fb-7538-42bf-84e8-7ccd7eef9355
  6. cpe:2.3:o:paloaltonetworks:pan-os:10.2.11:h9:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 34
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    457824c9-4a39-4570-b697-f375aef47a04
  7. cpe:2.3:o:paloaltonetworks:pan-os:10.1.14:h6:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 5
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    6643574d-c024-440c-9392-004b7fa4498f
  8. cpe:2.3:o:paloaltonetworks:pan-os:10.2.9:h11:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 15
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    ceb258ee-2c6e-4a63-b04c-89c5f76b0878
  9. cpe:2.3:o:paloaltonetworks:pan-os:10.2.11:h6:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 33
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    c69b22c4-6e7d-4f39-b86c-d408670cdc42
  10. cpe:2.3:o:paloaltonetworks:pan-os:10.2.9:h1:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 14
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    8c7e9211-7041-4720-b4b9-3ea95d425263
  11. cpe:2.3:o:paloaltonetworks:pan-os:10.2.10:h7:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 26
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    593afe7a-cb37-4156-a2b8-646a317f3176
  12. cpe:2.3:o:paloaltonetworks:pan-os:10.2.12:h2:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 37
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    8ea4c2a7-18cd-4232-b08c-99befe497a57
  13. cpe:2.3:o:paloaltonetworks:pan-os:11.1.2:h14:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 44
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    5f6acdff-947e-4175-8a2a-8b43b86aa8b0
  14. cpe:2.3:o:paloaltonetworks:pan-os:11.1.3:h1:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 50
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    86053616-71fb-4f6e-8b1e-97c2da6c08a8
  15. cpe:2.3:o:paloaltonetworks:pan-os:11.1.3:h2:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 53
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    9a3435a9-2100-4eb3-b20c-6a194a742bcd
  16. cpe:2.3:o:paloaltonetworks:pan-os:11.1.4:h1:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 57
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    be3f7369-9f35-409a-9f47-45a959592dfa
  17. cpe:2.3:o:paloaltonetworks:pan-os:11.1.2:h1:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 42
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    275872c1-1ebb-4447-8c9f-347f757bff42
  18. cpe:2.3:o:paloaltonetworks:pan-os:10.2.8:h10:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 7
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    f70fc9df-10c9-4ae5-b64b-3153e2e4e9e8
  19. cpe:2.3:o:paloaltonetworks:pan-os:10.2.9:h9:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 19
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    4e9eb9c6-78ba-4c66-a4bd-856bf27388ce
  20. cpe:2.3:o:paloaltonetworks:pan-os:10.2.12:h3:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 38
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    357b747e-f960-4aa9-8696-b3bd89933630
  21. cpe:2.3:o:paloaltonetworks:pan-os:10.1.14:-:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 2
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    b41a7115-a370-49e1-b162-24803e6dd2cb
  22. cpe:2.3:o:paloaltonetworks:pan-os:10.2.11:h1:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 29
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    010f170d-438e-4a57-98b9-e7522fd95fc3
  23. cpe:2.3:o:paloaltonetworks:pan-os:11.1.2:h12:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 43
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    f83e2987-f7b0-486c-8dc3-3c4a8b76f295
  24. cpe:2.3:o:paloaltonetworks:pan-os:11.1.2:h9:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 48
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    bc83c63b-54c8-4667-8742-30a5477414b5
  25. cpe:2.3:o:paloaltonetworks:pan-os:10.2.12:h1:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 36
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    fb95d77f-1263-4d47-a0bb-94a6da937115
  26. cpe:2.3:o:paloaltonetworks:pan-os:11.1.3:h6:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 55
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    d953b45f-7f10-4087-ae3a-bd9ab977af8b
  27. cpe:2.3:o:paloaltonetworks:pan-os:10.2.10:h10:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 21
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    ff7fcd8b-80df-4004-a9d2-4ee884f089a6
  28. cpe:2.3:o:paloaltonetworks:pan-os:10.2.10:-:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 20
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    03c5abf2-8c53-4376-8a64-6cb34e18e77c
  29. cpe:2.3:o:paloaltonetworks:pan-os:11.1.2:h3:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 46
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    4f36a8ca-4b15-4a88-ba51-2346506de6e5
  30. cpe:2.3:o:paloaltonetworks:pan-os:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 0
    Logic
    OR
    Version bounds
    from including 11.1.0; through including 11.1.1
    Match ID
    eaf9fd1f-1b8d-42a7-ab52-ba1f687c87bd
  31. cpe:2.3:o:paloaltonetworks:pan-os:11.1.2:h15:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 45
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    6302e536-5b1a-45f6-996e-847f22c3c997
  32. cpe:2.3:o:paloaltonetworks:pan-os:10.2.9:h14:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 16
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    0f481b0e-2353-4ab0-8a98-b0efbc409868
  33. cpe:2.3:o:paloaltonetworks:pan-os:10.2.8:h4:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 12
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    e5e6a893-2994-40a3-af35-8af068b0de42
  34. cpe:2.3:o:paloaltonetworks:pan-os:10.2.8:h3:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 11
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    cba2b4fa-16c2-41b9-856d-edc0caf7a164
  35. cpe:2.3:o:paloaltonetworks:pan-os:10.2.11:h4:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 32
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    fee28628-e969-44fc-b577-066db98bbda0
  36. cpe:2.3:o:paloaltonetworks:pan-os:10.1.14:h2:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 3
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    65949a49-03a7-491c-b327-127f050ac4f6
  37. cpe:2.3:o:paloaltonetworks:pan-os:10.1.14:h4:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 4
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    e8acb147-b4c1-4964-b538-eaa117cc6dc1
  38. cpe:2.3:o:paloaltonetworks:pan-os:11.1.2:-:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 41
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    5f7627b3-a463-4570-ba23-663feb7b4a8b
  39. cpe:2.3:o:paloaltonetworks:pan-os:10.2.8:-:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 6
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    5d64390f-f870-4dbf-b0fe-bcdfe58c8685
  40. cpe:2.3:o:paloaltonetworks:pan-os:10.2.10:h4:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 24
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    6cf8f985-7e51-49e6-857a-faaf027f5611
  41. cpe:2.3:o:paloaltonetworks:pan-os:10.2.11:-:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 28
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    2b3d7dba-c90c-451d-94c3-8b7066826308
  42. cpe:2.3:o:paloaltonetworks:pan-os:10.2.10:h2:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 22
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    872bc747-512a-4872-ac86-e7f1dc589f47
  43. cpe:2.3:o:paloaltonetworks:pan-os:11.1.3:h11:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 52
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    a0e89d5d-3e2a-427c-90a9-2fe6123372df
  44. cpe:2.3:o:paloaltonetworks:pan-os:10.2.10:h5:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 25
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    b437dcea-aba3-41ca-b320-97ec430f1122
  45. cpe:2.3:o:paloaltonetworks:pan-os:10.2.10:h9:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 27
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    a9f032c2-3202-479b-8c70-277f6871a4a4
  46. cpe:2.3:o:paloaltonetworks:pan-os:11.1.4:h4:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 58
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    e9db4da9-2262-4e9e-b3a1-49d261d01295
  47. cpe:2.3:o:paloaltonetworks:pan-os:10.2.8:h18:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 10
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    347e5938-24ff-4c2c-b823-988d34706e24
  48. cpe:2.3:o:paloaltonetworks:pan-os:10.2.9:h16:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 17
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    3f7fc771-527f-4619-b785-6ae1f4722074
  49. cpe:2.3:o:paloaltonetworks:pan-os:10.2.9:h18:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 18
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    ccc2a6da-eb48-42cd-9234-a80c3f6aefae
  50. cpe:2.3:o:paloaltonetworks:pan-os:10.2.11:h3:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 31
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    f3d096d4-e60e-4d4c-9122-c36b775b4a6f
  51. cpe:2.3:o:paloaltonetworks:pan-os:11.1.4:-:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 56
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    df83eaa1-49e1-4ad0-a049-f1b3065950bc
  52. cpe:2.3:o:paloaltonetworks:pan-os:10.2.13:-:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 39
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    c2b871a6-0636-42a0-9573-6f693d7753ad
  53. cpe:2.3:o:paloaltonetworks:pan-os:10.2.8:h13:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 8
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    c3d6d552-6f33-496a-a505-5f59df3b487b
  54. cpe:2.3:o:paloaltonetworks:pan-os:11.1.3:h10:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 51
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    0d1e3767-9517-4181-8355-dc0fb1139c95
  55. cpe:2.3:o:paloaltonetworks:pan-os:10.2.9:-:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 13
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    d814f3a3-5e9d-426d-a654-1346d9ece9b3
  56. cpe:2.3:o:paloaltonetworks:pan-os:10.2.11:h2:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 30
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    ad8795be-5cc2-443d-99ad-bd6985cadba7
  57. cpe:2.3:o:paloaltonetworks:pan-os:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 1
    Logic
    OR
    Version bounds
    from including 11.2.0; through excluding 11.2.3
    Match ID
    abc296b2-c123-4767-83ae-81c29e9a8e93
  58. cpe:2.3:o:paloaltonetworks:pan-os:11.1.2:h4:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 47
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    f6ced1cc-d63c-4a10-9035-c461ca35e584
  59. cpe:2.3:o:paloaltonetworks:pan-os:10.2.10:h3:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 23
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    67f527d0-f85b-4b83-aea5-ba636fc89210
NVD CPE · OPERATING SYSTEMpaloaltonetworkspan-osEnvironmental constraint · 24 assertions
Any version (unconstrained) (>= 10.2.11, < 11.2.3); Version 10.2.10; Version 10.2.8; Version 10.2.9Canonical identity product-612afb736440531327cd224402d663e14e2a3f421cc65267d8acade0f3b99df7Linked exact
Scope constrained
Inspect raw assertions
  1. cpe:2.3:o:paloaltonetworks:pan-os:10.2.8:-:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    1 · node/1 · match 1
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    5d64390f-f870-4dbf-b0fe-bcdfe58c8685
  2. cpe:2.3:o:paloaltonetworks:pan-os:10.2.10:h7:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    1 · node/1 · match 22
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    593afe7a-cb37-4156-a2b8-646a317f3176
  3. cpe:2.3:o:paloaltonetworks:pan-os:10.2.9:h9:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    1 · node/1 · match 15
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    4e9eb9c6-78ba-4c66-a4bd-856bf27388ce
  4. cpe:2.3:o:paloaltonetworks:pan-os:10.2.9:-:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    1 · node/1 · match 9
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    d814f3a3-5e9d-426d-a654-1346d9ece9b3
  5. cpe:2.3:o:paloaltonetworks:pan-os:10.2.9:h1:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    1 · node/1 · match 10
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    8c7e9211-7041-4720-b4b9-3ea95d425263
  6. cpe:2.3:o:paloaltonetworks:pan-os:10.2.9:h11:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    1 · node/1 · match 11
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    ceb258ee-2c6e-4a63-b04c-89c5f76b0878
  7. cpe:2.3:o:paloaltonetworks:pan-os:10.2.10:h4:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    1 · node/1 · match 20
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    6cf8f985-7e51-49e6-857a-faaf027f5611
  8. cpe:2.3:o:paloaltonetworks:pan-os:10.2.8:h3:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    1 · node/1 · match 7
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    cba2b4fa-16c2-41b9-856d-edc0caf7a164
  9. cpe:2.3:o:paloaltonetworks:pan-os:10.2.9:h18:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    1 · node/1 · match 14
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    ccc2a6da-eb48-42cd-9234-a80c3f6aefae
  10. cpe:2.3:o:paloaltonetworks:pan-os:10.2.10:-:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    1 · node/1 · match 16
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    03c5abf2-8c53-4376-8a64-6cb34e18e77c
  11. cpe:2.3:o:paloaltonetworks:pan-os:10.2.10:h2:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    1 · node/1 · match 18
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    872bc747-512a-4872-ac86-e7f1dc589f47
  12. cpe:2.3:o:paloaltonetworks:pan-os:10.2.8:h4:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    1 · node/1 · match 8
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    e5e6a893-2994-40a3-af35-8af068b0de42
  13. cpe:2.3:o:paloaltonetworks:pan-os:10.2.8:h10:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    1 · node/1 · match 2
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    f70fc9df-10c9-4ae5-b64b-3153e2e4e9e8
  14. cpe:2.3:o:paloaltonetworks:pan-os:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    1 · node/1 · match 0
    Logic
    OR
    Version bounds
    from including 10.2.11; through excluding 11.2.3
    Match ID
    44337774-f205-4121-adec-7d4af7f9208c
  15. cpe:2.3:o:paloaltonetworks:pan-os:10.2.10:h10:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    1 · node/1 · match 17
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    ff7fcd8b-80df-4004-a9d2-4ee884f089a6
  16. cpe:2.3:o:paloaltonetworks:pan-os:10.2.8:h13:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    1 · node/1 · match 3
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    c3d6d552-6f33-496a-a505-5f59df3b487b
  17. cpe:2.3:o:paloaltonetworks:pan-os:10.2.8:h19:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    1 · node/1 · match 6
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    c889402f-138a-45b9-bbcf-91fd18a0b810
  18. cpe:2.3:o:paloaltonetworks:pan-os:10.2.8:h15:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    1 · node/1 · match 4
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    d1ecd1dc-5a05-4e4f-97f5-136ce777fab3
  19. cpe:2.3:o:paloaltonetworks:pan-os:10.2.9:h14:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    1 · node/1 · match 12
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    0f481b0e-2353-4ab0-8a98-b0efbc409868
  20. cpe:2.3:o:paloaltonetworks:pan-os:10.2.9:h16:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    1 · node/1 · match 13
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    3f7fc771-527f-4619-b785-6ae1f4722074
  21. cpe:2.3:o:paloaltonetworks:pan-os:10.2.10:h9:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    1 · node/1 · match 23
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    a9f032c2-3202-479b-8c70-277f6871a4a4
  22. cpe:2.3:o:paloaltonetworks:pan-os:10.2.8:h18:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    1 · node/1 · match 5
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    347e5938-24ff-4c2c-b823-988d34706e24
  23. cpe:2.3:o:paloaltonetworks:pan-os:10.2.10:h3:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    1 · node/1 · match 19
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    67f527d0-f85b-4b83-aea5-ba636fc89210
  24. cpe:2.3:o:paloaltonetworks:pan-os:10.2.10:h5:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    1 · node/1 · match 21
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    b437dcea-aba3-41ca-b320-97ec430f1122
NVD CPE · APPLICATIONpaloaltonetworksprisma_accessVulnerable target · 1 assertions
Version not applicableCanonical identity product-4f5509d773574c4909e330faffacb5fc98a0d4f3df06311fc992145a72df1fe9Linked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:a:paloaltonetworks:prisma_access:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    ffb6fbc7-deeb-4571-bcf9-92345a4b614a

Affected-product evidence

Accepted scope and product mapping

0 canonical links · 0 source-reported links

Applicability remains source-scoped; safety and exposure remain unassessed.

Assessments

CVSS by origin

7.5
NVDCVSS 3.1 · role Primary · priority eligiblevalid_matchCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
8.7
psirt@paloaltonetworks.comCVSS 4.0 · role Secondary · priority eligiblevalid_matchCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:C/RE:M/U:Amber
8.7
palo_altoCVSS 4.0 · role unknown · display onlyDirect record assessment retained outside normalized eligibilityCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L/AU:N/R:U/V:C/RE:M/U:Amber
7.1
palo_altoCVSS 4.0 · role unknown · display onlyDirect record assessment retained outside normalized eligibilityCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L/AU:N/R:U/V:C/RE:M/U:Amber

Evidence boundaries

  • KEV membership is authoritative for the catalog, not proof of exposure in any environment.
  • EPSS is a dated model probability and not an individual-environment prediction.
  • Affected or fixed status applies only to the exact cited product and version scope; remaining scope stays source-scoped.
  • NVD-carried upstream facts remain derivative; independent corroboration requires a separately authored source.
  • Only NVD metrics validated under the generation-bound calculator are Public Priority eligible; direct CVE record metrics remain display-only.
  • NVD CVSS source eligibility is closed: NVD-authored, exact record-source, or registered same-CVE container origin; unmapped sources remain display-only.
  • Affected-product evidence remains source-scoped; canonical linkage is required before applicability scoring.
  • Core replay supports the active and immediately prior generation; retrospective valid-at replay is deferred.
  • OSV aggregation and OSV-converted NVD material are not independent corroboration.
  • Red Hat facts are vendor assertions for the exact supplied products.
  • Nonmembership and not-yet-observed states are not proof of safety.