CVE Vulnerabilities

CVE-2024-3387

Inadequate Encryption Strength

Published: Apr 10, 2024 | Modified: Jan 30, 2026
CVSS 3.x
5.9
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

A weak (low bit strength) device certificate in Palo Alto Networks Panorama software enables an attacker to perform a meddler-in-the-middle (MitM) attack to capture encrypted traffic between the Panorama management server and the firewalls it manages. With sufficient computing resources, the attacker could break encrypted communication and expose sensitive information that is shared between the management server and the firewalls.

Weakness

The product stores or transmits sensitive data using an encryption scheme that is theoretically sound, but is not strong enough for the level of protection required.

Affected Software

NameVendorStart VersionEnd Version
Pan-osPaloaltonetworks10.1.0 (including)10.1.12 (excluding)
Pan-osPaloaltonetworks10.2.0 (including)10.2.7 (excluding)
Pan-osPaloaltonetworks11.0.0 (including)11.0.4 (excluding)
Pan-osPaloaltonetworks10.2.7-h1 (including)10.2.7-h1 (including)
Pan-osPaloaltonetworks10.2.7-h2 (including)10.2.7-h2 (including)
Pan-osPaloaltonetworks10.2.7-h3 (including)10.2.7-h3 (including)
Pan-osPaloaltonetworks10.2.7-h4 (including)10.2.7-h4 (including)
Pan-osPaloaltonetworks10.2.7-h5 (including)10.2.7-h5 (including)
Pan-osPaloaltonetworks10.2.7-h6 (including)10.2.7-h6 (including)

Potential Mitigations

References