Executive brief
An SQL injection vulnerability in Palo Alto Networks Expedition allows unauthenticated network-based attackers to access sensitive database contents, including password hashes, device configurations, and API keys. Exploitation also enables the creation and reading of arbitrary files on the underlying system.
Affected products
- Palo Alto Networks Expedition 1.2.0 to 1.2.96 (excluding 1.2.96)
Timeline
- 2024-10-09: disclosed: Initial disclosure by Palo Alto Networks
- 2024-10-09: advisory: Vendor advisory PAN-SA-2024-0010 published
- 2024-11-14: kev added: Added to CISA Known Exploited Vulnerabilities (KEV) catalog
- 2024-11-14: exploited: Confirmed exploitation in the wild per CISA KEV entry