NULL pointer dereference in Palo Alto PAN-OS - CVE-2024-9472
Published: November 19, 2024
Palo Alto PAN-OS
Detailed vulnerability description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a NULL pointer dereference error when Decryption policy is enabled. A remote attacker can send specially crafted traffic through the data plane and perform a denial of service (DoS) attack.
How to mitigate CVE-2024-9472
Install update from vendor's website.
Note, the vulnerability affects only PA-800 Series, PA-3200 Series, PA-5200 Series, and PA-7000 Series devices.