CRITICAL🇵🇱 Wersja polska

CVE-2024-9464

CVSS 9.3v4.0pub. 2024-10-09upd. 2024-10-17

An OS command injection vulnerability in Palo Alto Networks Expedition allows an authenticated attacker to run arbitrary OS commands as root in Expedition, resulting in disclosure of usernames, cleartext passwords, device configurations, and device API keys of PAN-OS firewalls.

🤖 AI Analysis
How it works

An authenticated attacker can inject malicious operating system commands into a vulnerable component of the Expedition application (CWE-78). These commands are then executed by the system with root privileges, without requiring additional user interaction or fulfillment of special technical conditions. The attack vector is network-based, and attack complexity is low, which significantly lowers the entry threshold for a potential attacker.

Impact

The attacker gains full control over the Expedition system with root privileges, leading to disclosure of usernames, passwords in cleartext form, device configurations, and PAN-OS firewall API keys. Compromise of this data may enable further attacks on the managed network infrastructure.

Mitigation & patch

Apply patches available from the vendor according to the references — see advisory PAN-SA-2024-0010 published by Palo Alto Networks

Who is affected

Palo Alto Networks Expedition — versions indicated in the vendor references (advisory PAN-SA-2024-0010)

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:C/RE:H/U:Amber
  • Palo Alto Networks Expedition

    APP
    Paloaltonetworks
    1.2.0 – 1.2.96 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
FirewallCommand Injection
CWE
References

Related vulnerabilities

CVE-2024-9463CRITICAL9.9⚠ KEVPL ✓same product

Command injection w Palo Alto Networks Expedition — nieautoryzowane RCE jako root

CVE-2024-9465CRITICAL9.2⚠ KEVPL ✓same product

SQL Injection w Palo Alto Networks Expedition — dostęp do danych i plików

CVE-2024-5910CRITICAL9.3⚠ KEVPL ✓same product

Brak uwierzytelnienia w Palo Alto Networks Expedition — przejęcie konta admina

CVE-2025-0103CRITICAL9.2PL ✓same product

SQL Injection w Palo Alto Networks Expedition — ujawnienie danych i odczyt plików

CVE-2018-10143CRITICAL9.8PL ✓same product

Palo Alto Networks Expedition — nieautoryzowane wykonanie poleceń systemowych