CVE-2024-2550

A null pointer dereference vulnerability in the GlobalProtect gateway in Palo Alto Networks PAN-OS software enables an unauthenticated attacker to stop the GlobalProtect service on the firewall by sending a specially crafted packet that causes a denial of service (DoS) condition. Repeated attempts to trigger this condition result in the firewall entering maintenance mode.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
palo_altoCNA
---
---
CISA-ADPADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 30%
VendorProductVersion
paloaltonetworkspan-os
10.2.0 ≤
𝑥
< 10.2.7
paloaltonetworkspan-os
11.0.0 ≤
𝑥
< 11.0.6
paloaltonetworkspan-os
11.1.0 ≤
𝑥
< 11.1.4
paloaltonetworkspan-os
10.2.7:h1
paloaltonetworkspan-os
10.2.7:h12
paloaltonetworkspan-os
10.2.7:h16
paloaltonetworkspan-os
10.2.7:h18
paloaltonetworkspan-os
10.2.7:h19
paloaltonetworkspan-os
10.2.7:h3
paloaltonetworkspan-os
10.2.7:h6
paloaltonetworkspan-os
10.2.7:h8
paloaltonetworkspan-os
10.2.8
paloaltonetworkspan-os
10.2.8:h10
paloaltonetworkspan-os
10.2.8:h13
paloaltonetworkspan-os
10.2.8:h15
paloaltonetworkspan-os
10.2.8:h3
paloaltonetworkspan-os
10.2.8:h4
paloaltonetworkspan-os
10.2.9
paloaltonetworkspan-os
10.2.9:h1
paloaltonetworkspan-os
10.2.9:h11
paloaltonetworkspan-os
10.2.9:h14
paloaltonetworkspan-os
10.2.9:h16
paloaltonetworkspan-os
10.2.9:h9
paloaltonetworkspan-os
10.2.10
paloaltonetworkspan-os
10.2.10:h2
paloaltonetworkspan-os
10.2.10:h3
paloaltonetworkspan-os
10.2.10:h4
paloaltonetworkspan-os
10.2.10:h5
paloaltonetworkspan-os
10.2.10:h7
paloaltonetworkspan-os
10.2.10:h9
paloaltonetworkspan-os
11.1.4
paloaltonetworkspan-os
11.1.4:h1
paloaltonetworkspan-os
11.1.4:h4
paloaltonetworkspan-os
11.1.4:h7
𝑥
= Vulnerable software versions