An OS command injection vulnerability in Palo Alto Networks Expedition allows an authenticated attacker to run arbitrary OS commands as root in Expedition, resulting in disclosure of usernames, cleartext passwords, device configurations, and device API keys of PAN-OS firewalls.
An authenticated attacker can inject malicious operating system commands into a vulnerable component of the Expedition application (CWE-78). These commands are then executed by the system with root privileges, without requiring additional user interaction or fulfillment of special technical conditions. The attack vector is network-based, and attack complexity is low, which significantly lowers the entry threshold for a potential attacker.
The attacker gains full control over the Expedition system with root privileges, leading to disclosure of usernames, passwords in cleartext form, device configurations, and PAN-OS firewall API keys. Compromise of this data may enable further attacks on the managed network infrastructure.
Apply patches available from the vendor according to the references — see advisory PAN-SA-2024-0010 published by Palo Alto Networks
Palo Alto Networks Expedition — versions indicated in the vendor references (advisory PAN-SA-2024-0010)
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:C/RE:H/U:AmberPalo Alto Networks Expedition
APPPaloaltonetworks1.2.0 – 1.2.96 (excl.)
Related vulnerabilities
Command injection w Palo Alto Networks Expedition — nieautoryzowane RCE jako root
SQL Injection w Palo Alto Networks Expedition — dostęp do danych i plików
Brak uwierzytelnienia w Palo Alto Networks Expedition — przejęcie konta admina
SQL Injection w Palo Alto Networks Expedition — ujawnienie danych i odczyt plików
Palo Alto Networks Expedition — nieautoryzowane wykonanie poleceń systemowych