A memory corruption vulnerability in the processing of tunnel traffic in Palo Alto Networks PAN-OS® software allows an authenticated user to initiate system reboots using a maliciously crafted packet. Repeated attempts to initiate a reboot causes the firewall to enter maintenance mode.
Panorama, Cloud NGFW, and Prisma® Access are not impacted by this vulnerability.
This vulnerability affects PAN-OS firewalls configured with one or more of the following:
- IPSec Tunnels
- GlobalProtect Gateways (Remote Access)
Palo Alto Networks is not aware of any malicious exploitation of this issue.