An SQL injection vulnerability in Palo Alto Networks Expedition enables an authenticated attacker to reveal Expedition database contents, such as password hashes, usernames, device configurations, and device API keys. This vulnerability also enables attackers to create and read arbitrary files on the Expedition system.
An attacker with access to the Expedition application can inject malicious SQL queries (SQL injection, CWE-89) into vulnerable entry points of the application. This grants them the ability to read the contents of the Expedition system database, including password hashes, usernames, network device configurations, and API keys. Additionally, the vulnerability allows for creating and reading arbitrary files in the Expedition server filesystem.
An attacker can seize confidential authentication and configuration data of managed network devices, which consequently may lead to compromise of the entire network infrastructure. The ability to create and read system files additionally expands the attack surface beyond the database itself.
Apply patches available from the vendor according to the references: https://security.paloaltonetworks.com/PAN-SA-2025-0001. Additionally, it is recommended to restrict access to the Expedition interface exclusively to trusted users and administrative networks.
Palo Alto Networks Expedition — versions specified in the vendor references (security.paloaltonetworks.com/PAN-SA-2025-0001)
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:C/RE:H/U:AmberPalo Alto Networks Expedition
APPPaloaltonetworks< 1.2.101
Related vulnerabilities
Command injection w Palo Alto Networks Expedition — nieautoryzowane RCE jako root
SQL Injection w Palo Alto Networks Expedition — dostęp do danych i plików
Brak uwierzytelnienia w Palo Alto Networks Expedition — przejęcie konta admina
OS command injection w Palo Alto Networks Expedition umożliwiający RCE jako root
Palo Alto Networks Expedition — nieautoryzowane wykonanie poleceń systemowych