CVE-2024-9465
Description
An SQL injection vulnerability in Palo Alto Networks Expedition allows an unauthenticated attacker to reveal Expedition database contents, such as password hashes, usernames, device configurations, and device API keys. With this, attackers can also create and read arbitrary files on the Expedition system.
Summary dbcve.org
Palo Alto Networks Expedition contains an unauthenticated SQL injection vulnerability that allows remote attackers to extract sensitive database contents including password hashes, usernames, device configurations, and API keys. The vulnerability additionally permits attackers to create and read arbitrary files on the underlying operating system, greatly amplifying the impact beyond data exfiltration.
Mitigation
Apply the vendor-supplied patch for CVE-2024-9465 immediately; if patching is not immediately feasible, restrict network access to Expedition systems to trusted administrative networks only.