Back

MEDIUM

PAN-OS: Predefined Decryption Exclusions Does Not Work as Intended

Published Apr 10, 2024

Description

An incorrect string comparison vulnerability in Palo Alto Networks PAN-OS software prevents Predefined Decryption Exclusions from functioning as intended. This can cause traffic destined for domains that are not specified in Predefined Decryption Exclusions to be unintentionally excluded from decryption.

Affected products

Remediation

Vendor solution

This issue is fixed in 9.0.17-h2, 9.0.18, 9.1.17, 10.0.13, 10.1.9-h3, 10.1.10, 10.2.4-h2, 10.2.5, 11.0.1-h2, 11.0.2, 11.1.0 and all later PAN-OS versions.

Weaknesses (1)

References (2)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner palo_alto
Published Apr 10, 2024
Updated May 13, 2026
Reserved Apr 5, 2024
CISA Vulnrichment
Updated Apr 10, 2024
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner palo_alto
Published Apr 10, 2024
Updated May 13, 2026
Exploited since n/a
EUVD-2024-31975