Vulnerability Intelligence Report
Expedition: Unauthenticated OS Command Injection Vulnerability Leads to Firewall Credential Disclosure
CVE-2024-9463
An OS command injection vulnerability in Palo Alto Networks Expedition allows an unauthenticated attacker to run arbitrary OS commands as root in Expedition, resulting in disclosure of usernames, cleartext passwords, device configurations, and device API keys of PAN-OS firewalls.
CISA KEV
Nuclei Template
SSVC: Active Exploitation
Automatable
CVSS Base Score
9.9
CRITICAL
EPSS Probability:98.42%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-78 ↗CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| Palo Alto Networks | Expedition | 1.2.0 < 1.2.96 (affected) |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
CISA KEV
ACTIVE IN CATALOG
Nuclei Template
SCANNER AVAILABLE
EPSS Score
98.423%
GitHub Advisory
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | Palo Alto Networks, Inc. · Vendor · USA |
| Reserved | 2024-10-03T11:35:09 |
| Published | 2024-10-09T17:03:12 |
| Patch Date | 2024-10-09 |
| Last Updated | 2025-10-21T22:55:42 |
Community Chatter & Buzz