CVE-2024-3393 PAN-OS DNS Security DoS — Unauthenticated Firewall Crash Forces Maintenance Mode, Perimeter Security Collapse — Threadlinqs Intelligence
As of 2026-05-30, CVE-2024-3393 PAN-OS DNS Security DoS — Unauthenticated Firewall Crash Forces Maintenance Mode, Perimeter Security Collapse is a high-severity vulnerability threat attributed to a Unattributed-nexus actor, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 21 indicators of compromise.
Threat ID: TL-2026-0112 · Severity: HIGH · Status: PATCHED · Category: VULNERABILITY
Attribution: Unattributed · DESTRUCTION
CVE-2024-3393 is an actively exploited Denial-of-Service vulnerability in Palo Alto Networks PAN-OS DNS Security feature (CVSS 8.7). An unauthenticated attacker sends a specially crafted DNS packet
CVE-2024-3393 is a critical Denial-of-Service vulnerability in Palo Alto Networks PAN-OS software, specifically in the DNS Security feature. Published December 27, 2024, the vulnerability was discovered in production use — Palo Alto confirms customers experienced DoS when their firewalls blocked malicious DNS packets that triggered the condition.
**V1 CORRECTION: The v1 title references 'MoltBot Vulnerability Campaign.' 'MoltBot' does NOT exist in any security vendor database, Malpedia, MalwareBazaar, or any primary source. It is V1 FABRICATION. The CVE-2024-3393 vulnerability is real and actively exploited, but there is no malware called 'MoltBot' associated with it. This entry covers the verified CVE only.**
**VULNERABILITY DETAILS:**
The vulnerability exists in PAN-OS's DNS Security processing pipeline. When the DNS Security feature is enabled with logging active, a specially crafted DNS packet sent through the firewall's data plane triggers an improper check for unusual or exceptional conditions (CWE-754), potentially combined with a buffer overread (CAPEC-540). This causes the firewall process to crash and the device to reboot.
**ATTACK CHARACTERISTICS:**
- **Unauthenticated**: No credentials required
- **Network-accessible**: Attack sent through the data plane (not management plane)
- **Low complexity**: No special conditions needed beyond DNS Security being enabled with logging
- **No user interaction**: Firewall processes the packet automatically
- **Repeatable**: Repeated attempts force the firewall into maintenance mode, completely disabling it
- **Automatable**: Palo Alto rates this as NOT automatable (requires specific packet crafting), but the exploit maturity is ATTACKED (confirmed exploitation)
**REQUIRED CONDITIONS FOR EXPOSURE:**
BOTH must be true:
1. DNS Security License OR Advanced DNS Security License must be applied
2. DNS Security logging must be enabled (log-level set to anything other than 'none')
Verification via CLI: `show config merged | match log-level` — if any entries show values other than 'log-level none;', the device is vulnerable.
**AFFECTED PRODUCTS:**
- PAN-OS 11.2: < 11.2.3
- PAN-OS 11.1: < 11.1.2-h16, < 11.1.3-h13, < 11.1.4-h7, < 11.1.5
- PAN-OS 10.2: >= 10.2.8 and < various hotfix versions
- PAN-OS 10.1: >= 10.1.14 and < 10.1.14-h8
- Prisma Access: >= 10.2.8 on PAN-OS (multiple affected versions)
- NOT affected: Cloud NGFW, Panorama M-Series, Panorama virtual appliances, PAN-OS 10.0, PAN-OS 9.1
**IMPACT — FIREWALL BECOMES THE VULNERABILITY:**
This vulnerability inverts the security model: the DNS Security feature designed to PROTECT the network becomes the attack vector that DISABLES the firewall. An attacker doesn't need to bypass the firewall — they crash it. Once in maintenance mode, ALL traffic passes unprotected or is blocked entirely depending on fail-open/fail-close configuration. For organizations depending on Palo Alto as their primary perimeter defense, this is a complete security posture collapse.
**EXPLOITATION CONTEXT:**
Palo Alto acknowledges 'customers experiencing this denial of service (DoS) when their firewall blocks malicious DNS packets that trigger this issue.' This means the vulnerability was discovered because LEGITIMATE DNS SECURITY DETECTIONS triggered the crash — the firewall was correctly blocking malicious DNS, but the blocking process itself caused the DoS. CERT-EE (Estonia) provided forensic assistance, suggesting exploitation was observed in European network defense operations.
**WORKAROUND:**
Set DNS Security log severity to 'none' in Anti-Spyware profiles. This reduces DNS Security visibility but prevents the crash. Note: this may block DNS traffic without generating log entries, creating a blind spot.
Target sectors: Technology, Government, Financial Services, Healthcare, Critical Infrastructure, Telecommunications
Target regions: Global
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 21 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
VULNERABILITY, HIGH, threat intelligence, cybersecurity, CVE-2024-3393, T1498.001, T1489, T1190, T1562.001, T1562.004, T1499.003, T1595.002, T1587.004, T1046, T1562.006