A Leader in the 2026 Gartner® Magic Quadrant™ for Endpoint Protection. Six years running.Six years. Gartner® Magic Quadrant™ Leader.Find Out Why
Experiencing a Breach?Blog
Get StartedContact Us
SentinelOne
  • Platform
    Platform Overview
    • Singularity Platform
      Welcome to Integrated Enterprise Security
    • AI for Security
      Leading the Way in AI-Powered Security Solutions
    • Securing AI
      Accelerate AI Adoption with Secure AI Tools, Apps, and Agents.
    • How It Works
      The Singularity XDR Difference
    • Singularity Marketplace
      One-Click Integrations to Unlock the Power of XDR
    • Pricing & Packaging
      Comparisons and Guidance at a Glance
    Data & AI
    • Purple AI
      Accelerate SecOps with Generative AI
    • Singularity Hyperautomation
      Easily Automate Security Processes
    • AI-SIEM
      The AI SIEM for the Autonomous SOC
    • AI Data Pipelines
      Security Data Pipeline for AI SIEM and Data Optimization
    • Singularity Data Lake
      AI-Powered, Unified Data Lake
    • Singularity Data Lake for Log Analytics
      Seamlessly Ingest Data from On-Prem, Cloud or Hybrid Environments
    Endpoint Security
    • Singularity Endpoint
      Autonomous Prevention, Detection, and Response
    • Singularity XDR
      Native & Open Protection, Detection, and Response
    • Singularity RemoteOps Forensics
      Orchestrate Forensics at Scale
    • Singularity Threat Intelligence
      Comprehensive Adversary Intelligence
    • Singularity Vulnerability Management
      Application & OS Vulnerability Management
    • Singularity Identity
      Identity Threat Detection and Response
    Cloud Security
    • Singularity Cloud Security
      Block Attacks with an AI-Powered CNAPP
    • Singularity Cloud Native Security
      Secure Cloud and Development Resources
    • Singularity Cloud Workload Security
      Real-Time Cloud Workload Protection Platform
    • Singularity Cloud Data Security
      AI-Powered Threat Detection for Cloud Storage
    • Singularity Cloud Security Posture Management
      Detect and Remediate Cloud Misconfigurations
    Securing AI
    • Prompt Security
      Secure AI Tools Across Your Enterprise
  • Why SentinelOne?
    Why SentinelOne?
    • Why SentinelOne?
      Cybersecurity Built for What’s Next
    • Our Customers
      Trusted by the World’s Leading Enterprises
    • Industry Recognition
      Tested and Proven by the Experts
    • About Us
      The Industry Leader in Autonomous Cybersecurity
    Compare SentinelOne
    • Arctic Wolf
    • Broadcom
    • CrowdStrike
    • Cybereason
    • Microsoft
    • Palo Alto Networks
    • Sophos
    • Splunk
    • Trellix
    • Trend Micro
    • Wiz
    Verticals
    • Energy
    • Federal Government
    • Finance
    • Healthcare
    • Higher Education
    • K-12 Education
    • Manufacturing
    • Retail
    • State and Local Government
  • Services
    Managed Services
    • Managed Services Overview
      Wayfinder Threat Detection & Response
    • Threat Hunting
      World-Class Expertise and Threat Intelligence
    • Managed Detection & Response
      24/7/365 Expert MDR Across Your Entire Environment
    • Incident Readiness & Response
      DFIR, Breach Readiness, & Compromise Assessments
    Support, Deployment, & Health
    • Technical Account Management
      Customer Success with Personalized Service
    • SentinelOne GO
      Guided Onboarding & Deployment Advisory
    • SentinelOne University
      Live and On-Demand Training
    • Services Overview
      Comprehensive Solutions for Seamless Security Operations
    • SentinelOne Community
      Community Login
  • Partners
    Our Network
    • MSSP Partners
      Succeed Faster with SentinelOne
    • Singularity Marketplace
      Extend the Power of S1 Technology
    • Cyber Risk Partners
      Enlist Pro Response and Advisory Teams
    • Technology Alliances
      Integrated, Enterprise-Scale Solutions
    • SentinelOne for AWS
      Hosted in AWS Regions Around the World
    • Channel Partners
      Deliver the Right Solutions, Together
    • SentinelOne for Google Cloud
      Unified, Autonomous Security Giving Defenders the Advantage at Global Scale
    • Partner Locator
      Your Go-to Source for Our Top Partners in Your Region
    Partner Portal→
  • Resources
    Resource Center
    • Case Studies
    • Data Sheets
    • eBooks
    • Reports
    • Videos
    • Webinars
    • Whitepapers
    • Events
    View All Resources→
    Blog
    • Feature Spotlight
    • For CISO/CIO
    • From the Front Lines
    • Identity
    • Cloud
    • macOS
    • SentinelOne Blog
    Blog→
    Tech Resources
    • SentinelLABS
    • Ransomware Anthology
    • Cybersecurity 101
  • About
    About SentinelOne
    • About SentinelOne
      The Industry Leader in Cybersecurity
    • Investor Relations
      Financial Information & Events
    • SentinelLABS
      Threat Research for the Modern Threat Hunter
    • Careers
      The Latest Job Opportunities
    • Press & News
      Company Announcements
    • Cybersecurity Blog
      The Latest Cybersecurity Threats, News, & More
    • FAQ
      Get Answers to Our Most Frequently Asked Questions
    • DataSet
      The Live Data Platform
    • S Foundation
      Securing a Safer Future for All
    • S Ventures
      Investing in the Next Generation of Security, Data and AI
  • Pricing
Get StartedContact Us
CVE Vulnerability Database
Vulnerability Database/CVE-2024-2551

CVE-2024-2551: Palo Alto PAN-OS DoS Vulnerability

CVE-2024-2551 is a null pointer dereference DoS flaw in Palo Alto Networks PAN-OS that lets unauthenticated attackers crash core services via crafted packets. This article covers technical details, affected versions, and mitigation.

Published: May 26, 2026

CVE-2024-2551 Overview

CVE-2024-2551 is a null pointer dereference vulnerability [CWE-476] in Palo Alto Networks PAN-OS software. An unauthenticated attacker can stop a core system service on the firewall by sending a crafted packet through the data plane. Repeated exploitation attempts force the firewall into maintenance mode, removing it from active service.

The flaw affects multiple PAN-OS versions, including 10.2.4 and several hotfix releases. The vulnerability requires no privileges or user interaction and is exploitable across the network.

Critical Impact

Unauthenticated remote attackers can trigger a denial of service condition that stops core firewall services and forces the device into maintenance mode after repeated exploitation.

Affected Products

  • Palo Alto Networks PAN-OS 10.2.4
  • Palo Alto Networks PAN-OS 10.2.4-h2, 10.2.4-h3, 10.2.4-h4
  • Additional PAN-OS versions identified in the vendor advisory

Discovery Timeline

  • 2024-11-14 - CVE-2024-2551 published to NVD
  • 2025-01-24 - Last updated in NVD database

Technical Details for CVE-2024-2551

Vulnerability Analysis

The vulnerability resides in PAN-OS data plane packet processing. A crafted packet sent to the firewall triggers a null pointer dereference within a core system service. The dereference causes the affected service to terminate, interrupting traffic processing functions that depend on it.

Repeated triggering of the condition escalates impact beyond a single service crash. The firewall transitions into maintenance mode, a recovery state in which normal operation is suspended. Administrative intervention is required to restore the device to production.

Because the attack traverses the data plane, any network path that can deliver packets to the firewall's processing engine is a viable vector. Authentication is not required, and the attacker does not need to interact with management interfaces.

Root Cause

The root cause is improper validation of a pointer prior to dereference within PAN-OS packet handling logic. When the affected code path encounters specific malformed or unexpected packet content, it accesses a null pointer instead of a valid memory address. This triggers a fatal fault in the service process.

Attack Vector

The attack vector is network-based and unauthenticated. An attacker delivers a crafted packet through the data plane of a vulnerable PAN-OS firewall. The packet exercises the vulnerable code path and crashes the targeted service. The vulnerability does not yield code execution or data exposure but produces availability impact. Refer to the Palo Alto Networks Advisory for protocol-specific details.

Detection Methods for CVE-2024-2551

Indicators of Compromise

  • Unexpected restarts or crashes of core PAN-OS data plane services recorded in system logs
  • Firewall transitions into maintenance mode without administrator action
  • Repeated dataplane process termination events in the device system log
  • Loss of traffic forwarding correlated with inbound traffic from a single source

Detection Strategies

  • Monitor PAN-OS system logs for service restart and crash events linked to packet processing components
  • Alert on any maintenance mode transition events, which indicate cumulative service failures
  • Correlate firewall availability drops with packet capture data to identify the triggering source

Monitoring Recommendations

  • Forward PAN-OS system and configuration logs to a centralized SIEM for retention and correlation
  • Configure SNMP and syslog alerts for firewall health state changes and service failures
  • Track high availability (HA) failover events that may indicate an attacker disrupting the active peer

How to Mitigate CVE-2024-2551

Immediate Actions Required

  • Identify all PAN-OS devices running affected versions, including 10.2.4 and its hotfix branches
  • Apply the fixed PAN-OS release listed in the vendor advisory as soon as maintenance windows allow
  • Restrict data plane exposure of management and untrusted interfaces using access control lists where feasible
  • Verify high availability configurations so a single device failure does not disrupt traffic

Patch Information

Palo Alto Networks has published fixed PAN-OS versions and remediation guidance in the Palo Alto Networks Advisory for CVE-2024-2551. Administrators should consult the advisory to confirm the specific fixed release for each affected branch and upgrade accordingly.

Workarounds

  • Limit the network sources that can reach data plane interfaces using upstream filtering and zone-based policies
  • Deploy PAN-OS firewalls in active/passive HA pairs to reduce outage duration if a device enters maintenance mode
  • Apply threat prevention signatures published by Palo Alto Networks that address this issue, as referenced in the advisory
bash
# Example: review PAN-OS version and recent system events from CLI
show system info | match sw-version
show system logs system direction equal backward

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

  • Vulnerability Details
  • TypeDOS

  • Vendor/TechPaloaltonetworks Pan Os

  • SeverityHIGH

  • CVSS Score8.7

  • EPSS Probability0.31%

  • Known ExploitedNo
  • CVSS Vector
  • CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:C/RE:M/U:Amber
  • Impact Assessment
  • ConfidentialityLow
  • IntegrityNone
  • AvailabilityHigh
  • CWE References
  • CWE-476
  • Vendor Resources
  • Palo Alto Networks Advisory
  • Related CVEs
  • CVE-2024-3393: Palo Alto PAN-OS DNS Security DoS Flaw

  • CVE-2025-0114: Palo Alto PAN-OS GlobalProtect DoS Flaw

  • CVE-2025-0130: Palo Alto PAN-OS DoS Vulnerability

  • CVE-2024-2550: Palo Alto Networks PAN-OS DoS Vulnerability
Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.

Try SentinelOne
  • Get Started
  • Get a Demo
  • Product Tour
  • Why SentinelOne
  • Pricing & Packaging
  • FAQ
  • Contact
  • Contact Us
  • Customer Support
  • SentinelOne Status
  • Language
  • Platform
  • Singularity Platform
  • Singularity Endpoint
  • Singularity Cloud
  • Singularity AI-SIEM
  • Singularity Identity
  • Singularity Marketplace
  • Purple AI
  • Services
  • Wayfinder TDR
  • SentinelOne GO
  • Technical Account Management
  • Support Services
  • Verticals
  • Energy
  • Federal Government
  • Finance
  • Healthcare
  • Higher Education
  • K-12 Education
  • Manufacturing
  • Retail
  • State and Local Government
  • Cybersecurity for SMB
  • Resources
  • Blog
  • Labs
  • Case Studies
  • Videos
  • Product Tours
  • Events
  • Cybersecurity 101
  • eBooks
  • Webinars
  • Whitepapers
  • Press
  • News
  • Ransomware Anthology
  • Company
  • About Us
  • Our Customers
  • Careers
  • Partners
  • Legal & Compliance
  • Security & Compliance
  • Investor Relations
  • S Foundation
  • S Ventures

©2026 SentinelOne, All Rights Reserved.

Privacy Notice Terms of Use

English