Executive brief
An OS command injection vulnerability in Palo Alto Networks Expedition allows an unauthenticated remote attacker to execute arbitrary commands as root. Successful exploitation leads to the full compromise of the Expedition tool and the disclosure of sensitive PAN-OS firewall data, including credentials, configurations, and API keys.
Affected products
- Palo Alto Networks Expedition 1.2.0 to 1.2.96 (excluding 1.2.96)
Timeline
- 2024-10-09: disclosed: Initial disclosure by Palo Alto Networks
- 2024-10-09: patched: Fixed in Expedition 1.2.96
- 2024-11-14: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2024-11-14: exploited: Confirmed active exploitation in the wild