Junglewise Threat Intelligence

CVE-2024-9463: Palo Alto Networks Expedition OS Command Injection Vulnerability

CVE-2024-9463 · Severity: critical · CVSS 9.9 · Exploited in the wild · Published 2024-11-14

Technologies: Palo Alto Networks Expedition. Vendors: Palo Alto Networks, Palo Alto Networks.

Executive brief

An OS command injection vulnerability in Palo Alto Networks Expedition allows an unauthenticated remote attacker to execute arbitrary commands as root. Successful exploitation leads to the full compromise of the Expedition tool and the disclosure of sensitive PAN-OS firewall data, including credentials, configurations, and API keys.

Affected products

  • Palo Alto Networks Expedition 1.2.0 to 1.2.96 (excluding 1.2.96)

Timeline

  • 2024-10-09: disclosed: Initial disclosure by Palo Alto Networks
  • 2024-10-09: patched: Fixed in Expedition 1.2.96
  • 2024-11-14: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2024-11-14: exploited: Confirmed active exploitation in the wild

Related threats