CRITICAL🚩 CISA KEV⚡ EXPLOIT🇵🇱 Wersja polska

CVE-2024-9465

CVSS 9.2v4.0pub. 2024-10-09upd. 2025-11-04

An SQL injection vulnerability in Palo Alto Networks Expedition allows an unauthenticated attacker to reveal Expedition database contents, such as password hashes, usernames, device configurations, and device API keys. With this, attackers can also create and read arbitrary files on the Expedition system.

🤖 AI Analysis
How it works

An attacker without any authentication can send crafted SQL queries to the vulnerable Expedition application interface. Through SQL injection, they gain access to database contents, including password hashes, usernames, device configurations, and device API keys. Additionally, the vulnerability allows for creation and reading of arbitrary files in the Expedition server file system.

Impact

An attacker can steal authentication and configuration data of managed network devices (including API keys), which may lead to takeover of control over network infrastructure. The ability to write and read arbitrary files on the Expedition server creates a risk of further system compromise.

Mitigation & patch

Security patches available from the vendor should be applied immediately in accordance with the official Palo Alto Networks security advisory (PAN-SA-2024-0010). Until the update is applied, it is recommended to restrict network access to the Expedition system only to trusted hosts and monitor unauthorized access attempts.

Who is affected

Palo Alto Networks Expedition — versions indicated in vendor references (security.paloaltonetworks.com/PAN-SA-2024-0010)

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:C/RE:H/U:Amber
  • Palo Alto Networks Expedition

    APP
    Paloaltonetworks
    1.2.0 – 1.2.96 (excl.)

CISA KEV — detailsi

Vendori
Palo Alto Networks
Producti
Expedition
Added to KEVi
November 14, 2024
Remediation deadline (US Federal)i
December 5, 2024(overdue)
Required action (CISA)i

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CISA descriptioni

Palo Alto Networks Expedition contains a SQL injection vulnerability that allows an unauthenticated attacker to reveal Expedition database contents, such as password hashes, usernames, device configurations, and device API keys. With this, attackers can also create and read arbitrary files on the Expedition system.

🔴
IMMEDIATE ACTION
Actively exploited in the wild (CISA KEV). Patch immediately.
CISA DEADLINE: 5 grudnia 2024
Tags
SQLiAuth Bypass
CWE
References

Related vulnerabilities

CVE-2024-9463CRITICAL9.9⚠ KEVPL ✓same product

Command injection w Palo Alto Networks Expedition — nieautoryzowane RCE jako root

CVE-2024-5910CRITICAL9.3⚠ KEVPL ✓same product

Brak uwierzytelnienia w Palo Alto Networks Expedition — przejęcie konta admina

CVE-2025-0103CRITICAL9.2PL ✓same product

SQL Injection w Palo Alto Networks Expedition — ujawnienie danych i odczyt plików

CVE-2024-9464CRITICAL9.3PL ✓same product

OS command injection w Palo Alto Networks Expedition umożliwiający RCE jako root

CVE-2018-10143CRITICAL9.8PL ✓same product

Palo Alto Networks Expedition — nieautoryzowane wykonanie poleceń systemowych