CVE-2024-5910
Description
Missing authentication for a critical function in Palo Alto Networks Expedition can lead to an Expedition admin account takeover for attackers with network access to Expedition.
Note: Expedition is a tool aiding in configuration migration, tuning, and enrichment. Configuration secrets, credentials, and other data imported into Expedition is at risk due to this issue.
Summary dbcve.org
Palo Alto Networks Expedition contains a missing authentication vulnerability in a critical function that allows unauthenticated remote attackers with network access to hijack Expedition admin accounts. Since Expedition is used for configuration migration and enrichment, this exposure also threatens all secrets, credentials, and sensitive configuration data imported into the tool.
Mitigation
Apply the vendor patch or update that implements proper authentication for the critical function. As an interim measure, restrict network access to Expedition to trusted IP addresses only until the patch is deployed.