Junglewise Threat Intelligence

CVE-2024-9465: Palo Alto Networks Expedition SQL Injection Vulnerability

CVE-2024-9465 · Severity: critical · CVSS 9.2 · Exploited in the wild · Published 2024-11-14

Technologies: Palo Alto Networks Expedition. Vendors: Palo Alto Networks, Palo Alto Networks.

Executive brief

An SQL injection vulnerability in Palo Alto Networks Expedition allows unauthenticated network-based attackers to access sensitive database contents, including password hashes, device configurations, and API keys. Exploitation also enables the creation and reading of arbitrary files on the underlying system.

Affected products

  • Palo Alto Networks Expedition 1.2.0 to 1.2.96 (excluding 1.2.96)

Timeline

  • 2024-10-09: disclosed: Initial disclosure by Palo Alto Networks
  • 2024-10-09: advisory: Vendor advisory PAN-SA-2024-0010 published
  • 2024-11-14: kev added: Added to CISA Known Exploited Vulnerabilities (KEV) catalog
  • 2024-11-14: exploited: Confirmed exploitation in the wild per CISA KEV entry

Related threats