Vulnerability Intelligence Report
Expedition: Authenticated OS Command Injection Vulnerability Leads to Firewall Admin Credential Disclosure
CVE-2024-9464
An OS command injection vulnerability in Palo Alto Networks Expedition allows an authenticated attacker to run arbitrary OS commands as root in Expedition, resulting in disclosure of usernames, cleartext passwords, device configurations, and device API keys of PAN-OS firewalls.
No Active Exploit Signals
CVSS Base Score
9.3
CRITICAL
EPSS Probability:81.71%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-78 ↗CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| Palo Alto Networks | Expedition | 1.2.0 < 1.2.96 (affected) |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
EPSS Score
81.710%
GitHub Advisory
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | Palo Alto Networks, Inc. · Vendor · USA |
| Reserved | 2024-10-03T11:35:11 |
| Published | 2024-10-09T17:03:33 |
| Patch Date | 2024-10-09 |
| Last Updated | 2024-10-18T15:40:20 |
Community Chatter & Buzz