Prisma SD-WAN: Denial of Service (DoS) Vulnerability Through IPv6 Crafted Packet
Published May 13, 2026
4.9
MEDIUMCVSS 4.0
EPSS 0.17%
Description
A denial of service (DoS) vulnerability in Palo Alto Networks Prisma SD-WAN ION devices enables an unauthenticated attacker in a network adjacent to a Prisma SD-WAN ION device to cause a system disruption by sending a specially crafted IPv6 packet.
Affected products
-
- Version 6.3.0StatusaffectedConstraints<24.3.6
- Version 6.4.0StatusaffectedConstraints<25.1.8
- Version 6.5.0StatusaffectedConstraints<25.3.3
- Version 5.6.0StatusunaffectedConstraints-
- Version 6.1.0StatusunaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Palo Alto Networks | Prisma SD-WAN ION | unaffected |
|
- ≥ 6.3.1 · < 6.3.6
- ≥ 6.4.1 · < 6.4.3
- ≥ 6.5.1 · < 6.5.3
- 6.3.6
- 6.3.6
- 6.3.6
- 6.4.3
- 6.4.3
- 6.5.3
- 6.5.3
- 6.5.3
Running on/with
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
Version Minor Version Suggested Solution Prisma SD-WAN ION 6.5 6.5.1 through 6.5.3 Upgrade to 6.5.3-b15 or later. Prisma SD-WAN ION 6.4 6.4.1 through 6.4.3 Upgrade to 6.4.3-b8 or later. Prisma SD-WAN ION 6.3 6.3.1 through 6.3.6 Upgrade to 6.3.6-b10 or later. Prisma SD-WAN ION 6.1 No action needed. Prisma SD-WAN ION 5.6 No action needed.
References (2)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-30135 Advisory
- https://security.paloaltonetworks.com/CVE-2026-0243 vendor-advisoryVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-30135 | Advisory | |
| https://security.paloaltonetworks.com/CVE-2026-0243 | vendor-advisoryVendor Advisory |
Change history (0)
No recorded changes yet.