CVE-2024-3386
MEDIUMDescription
An incorrect string comparison vulnerability in Palo Alto Networks PAN-OS software prevents Predefined Decryption Exclusions from functioning as intended. This can cause traffic destined for domains that are not specified in Predefined Decryption Exclusions to be unintentionally excluded from decryption.
Is your site exposed to CVE-2024-3386?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| paloaltonetworks | pan-os |
| paloaltonetworks | pan-os |
| paloaltonetworks | pan-os |
| paloaltonetworks | pan-os |
| paloaltonetworks | pan-os |
| paloaltonetworks | pan-os |
| paloaltonetworks | pan-os |
| paloaltonetworks | pan-os |
| paloaltonetworks | pan-os |
| paloaltonetworks | pan-os |
| paloaltonetworks | pan-os |
| paloaltonetworks | pan-os |
References
Frequently Asked Questions
What is CVE-2024-3386? +
How severe is CVE-2024-3386? +
What products are affected by CVE-2024-3386? +
How do I check if I'm vulnerable to CVE-2024-3386? +
Related Vulnerabilities
Heimdall is a cloud native Identity Aware Proxy and Access Control Decision service. Prior to version 0.17.14, Heimdall handles URL-encoded …
uv is a Python package and project manager written in Rust. In versions 0.8.5 and earlier, remote ZIP archives were …
Heimdall is a cloud native Identity Aware Proxy and Access Control Decision service. Prior to version 0.17.14, Heimdall performs rule …
Heimdall is a cloud native Identity Aware Proxy and Access Control Decision service. Prior to version 0.17.14, Heimdall performs host …
When ALLOW_INSECURE_RAW_TEXT is enabled, whitespace-variant closing tags (e.g., </style\t>) are not recognized by the sanitizer but accepted by browsers as …
@hapi/content provided HTTP Content-* headers parsing. Prior to 6.0.2, Content.disposition() retained the last occurrence of each duplicate parameter while Content.type() …