CVE-2024-9463
Description
An OS command injection vulnerability in Palo Alto Networks Expedition allows an unauthenticated attacker to run arbitrary OS commands as root in Expedition, resulting in disclosure of usernames, cleartext passwords, device configurations, and device API keys of PAN-OS firewalls.
Summary dbcve.org
Palo Alto Networks Expedition contains an OS command injection vulnerability allowing unauthenticated attackers to execute arbitrary operating system commands with root privileges. This enables disclosure of sensitive data including usernames, cleartext passwords, device configurations, and PAN-OS firewall API keys.
Mitigation
Apply the vendor-provided patch for CVE-2024-9463 immediately. Restrict network access to Expedition systems until patched, and rotate any credentials that may have been exposed.