HIGH

CVE-2024-9463

Paloaltonetworks Expedition 2024-10-09 CVSS v3.1
CVSS
7.5
KEV

Description

An OS command injection vulnerability in Palo Alto Networks Expedition allows an unauthenticated attacker to run arbitrary OS commands as root in Expedition, resulting in disclosure of usernames, cleartext passwords, device configurations, and device API keys of PAN-OS firewalls.

Summary dbcve.org

Palo Alto Networks Expedition contains an OS command injection vulnerability allowing unauthenticated attackers to execute arbitrary operating system commands with root privileges. This enables disclosure of sensitive data including usernames, cleartext passwords, device configurations, and PAN-OS firewall API keys.

Mitigation

Apply the vendor-provided patch for CVE-2024-9463 immediately. Restrict network access to Expedition systems until patched, and rotate any credentials that may have been exposed.

Weakness (CWE)

CWE-78 OS Command Injection

EPSS Score

98.55%
Probability of exploitation in next 30 days
99.9th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE