« Volver al listado

CVE-2024-3382

Estado: AnalizadaAlta (7.5)—

A memory leak exists in Palo Alto Networks PAN-OS software that enables an attacker to send a burst of crafted packets through the firewall that eventually prevents the firewall from processing traffic. This issue applies only to PA-5400 Series devices that are running PAN-OS software with the SSL Forward Proxy feature enabled.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2024-3382",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2024-3382",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "yes"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2025-08-15T13:26:03.328273Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "psirt@paloaltonetworks.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.5,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 3.9
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.5,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "psirt@paloaltonetworks.com",
      "affectedData": [
        {
          "vendor": "Palo Alto Networks",
          "product": "PAN-OS",
          "versions": [
            {
              "status": "unaffected",
              "version": "9.0.0"
            },
            {
              "status": "unaffected",
              "version": "9.1.0"
            },
            {
              "status": "unaffected",
              "version": "10.1.0"
            },
            {
              "status": "affected",
              "changes": [
                {
                  "at": "10.2.7-h3",
                  "status": "unaffected"
                }
              ],
              "version": "10.2.0",
              "lessThan": "10.2.7-h3",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "changes": [
                {
                  "at": "11.0.4",
                  "status": "unaffected"
                }
              ],
              "version": "11.0.0",
              "lessThan": "11.0.4",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "changes": [
                {
                  "at": "11.1.2",
                  "status": "unaffected"
                }
              ],
              "version": "11.1.0",
              "lessThan": "11.1.2",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "Palo Alto Networks",
          "product": "Cloud NGFW",
          "versions": [
            {
              "status": "unaffected",
              "version": "All"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "Palo Alto Networks",
          "product": "Prisma Access",
          "versions": [
            {
              "status": "unaffected",
              "version": "All"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2024-04-10T17:15:56.793",
  "references": [
    {
      "url": "https://security.paloaltonetworks.com/CVE-2024-3382",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "psirt@paloaltonetworks.com"
    },
    {
      "url": "https://security.paloaltonetworks.com/CVE-2024-3382",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "psirt@paloaltonetworks.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-770"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-401"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "A memory leak exists in Palo Alto Networks PAN-OS software that enables an attacker to send a burst of crafted packets through the firewall that eventually prevents the firewall from processing traffic. This issue applies only to PA-5400 Series devices that are running PAN-OS software with the SSL Forward Proxy feature enabled."
    },
    {
      "lang": "es",
      "value": "Existe una fuga de memoria en el software PAN-OS de Palo Alto Networks que permite a un atacante enviar una ráfaga de paquetes manipulados a través del firewall que, en última instancia, impide que el firewall procese el tráfico. Este problema se aplica únicamente a los dispositivos de la serie PA-5400 que ejecutan el software PAN-OS con la función SSL Forward Proxy habilitada."
    }
  ],
  "lastModified": "2026-06-17T07:44:10.223",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:paloaltonetworks:pan-os:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "243077CD-5021-4DF3-8AC7-5B14F7FD9710",
              "versionEndExcluding": "10.2.7",
              "versionStartIncluding": "10.2.0"
            },
            {
              "criteria": "cpe:2.3:o:paloaltonetworks:pan-os:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "60048B56-C9E4-4492-9F4F-485AC3690FA6",
              "versionEndExcluding": "11.0.4",
              "versionStartIncluding": "11.0.0"
            },
            {
              "criteria": "cpe:2.3:o:paloaltonetworks:pan-os:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "21CFD38A-7AED-4CEE-BDA9-77D815689C58",
              "versionEndExcluding": "11.1.2",
              "versionStartIncluding": "11.1.0"
            },
            {
              "criteria": "cpe:2.3:o:paloaltonetworks:pan-os:10.2.7:-:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A8C42D98-CF8F-456B-9D57-80BBDC2C8E74"
            },
            {
              "criteria": "cpe:2.3:o:paloaltonetworks:pan-os:10.2.7:h1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B3AAD4BA-22DD-43D3-91F1-8A6F5FBBF029"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:paloaltonetworks:pa-5410:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "C702B085-D739-4E06-805F-D01144279071"
            },
            {
              "criteria": "cpe:2.3:h:paloaltonetworks:pa-5420:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "29237799-7DF5-478C-AE36-EC8E8416EAB7"
            },
            {
              "criteria": "cpe:2.3:h:paloaltonetworks:pa-5430:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "CEB69E29-2974-4963-96D6-E0C08D7777F4"
            },
            {
              "criteria": "cpe:2.3:h:paloaltonetworks:pa-5440:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "1F7914EA-FEA6-4911-9A47-4F516BEE6663"
            },
            {
              "criteria": "cpe:2.3:h:paloaltonetworks:pa-5445:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "37BC54A5-071C-4F62-87EB-2314CA019B08"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "psirt@paloaltonetworks.com"
}