Vulnerability Intelligence Report
Expedition: Cleartext Storage of Information Leads to Firewall Admin Credential Disclosure
CVE-2024-9466
A cleartext storage of sensitive information vulnerability in Palo Alto Networks Expedition allows an authenticated attacker to reveal firewall usernames, passwords, and API keys generated using those credentials.
No Active Exploit Signals
CVSS Base Score
8.2
HIGH
EPSS Probability:11.23%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-532 ↗CWE-532 Insertion of Sensitive Information into Log File
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| Palo Alto Networks | Expedition | 1.2.0 < 1.2.96 (affected) |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
EPSS Score
11.233%
GitHub Advisory
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | Palo Alto Networks, Inc. · Vendor · USA |
| Reserved | 2024-10-03T11:35:13 |
| Published | 2024-10-09T17:04:36 |
| Patch Date | 2024-10-09 |
| Last Updated | 2025-09-04T15:09:40 |
Community Chatter & Buzz