ZeroHour

CVE-2024-9463

KEVniche1

Unauthenticated OS Command Injection in Palo Alto Networks Expedition

CISA: Palo Alto Networks Expedition OS Command Injection Vulnerability

CVSS 4.0
9.9 critical
EPSS
99%p100
Published
()
KEV added
AI analysis

CVE-2024-9463 is a critical (CVSS 4.0: 9.9) OS command injection flaw (CWE-78) in Palo Alto Networks Expedition, the vendor's on-premises migration and firewall-management tool. An unauthenticated, network-adjacent attacker can send crafted input to trigger arbitrary operating system command execution with root privileges, requiring no credentials or user interaction. A successful compromise exposes the sensitive data Expedition holds for managed PAN-OS firewalls, including usernames, cleartext passwords, device configurations, and device API keys, which can enable follow-on attacks against the firewalls themselves. Any organization running an Expedition deployment, typically as a management appliance that is sometimes reachable from the internet, is affected. Exploitation is confirmed in the wild: Palo Alto Networks confirmed active exploitation (reported alongside SQL injection flaw CVE-2024-9465), CISA added it to the Known Exploited Vulnerabilities catalog on 2024-11-14, and EPSS assigns a 98.5% probability of exploitation within 30 days.

What to do: Upgrade Expedition to the vendor-fixed release per Palo Alto Networks' advisory, and remove or restrict internet exposure of the Expedition web interface; if patching is not immediately possible, CISA's required action is to apply vendor mitigations or discontinue use of the product. Because exploitation can disclose cleartext firewall usernames, passwords, and API keys, rotate those credentials and review firewall configurations and Expedition logs for signs of compromise, particularly given confirmed active exploitation alongside CVE-2024-9465.

Affected
Palo Alto Networks Expedition
Estimated exposure
nichelikely in the low thousands of on-premises deployments worldwide, with public scans showing only on the order of hundreds of internet-exposed instances — Expedition is a niche migration/firewall-management appliance deployed per organization rather than mass-market software, so exposure is bounded by the subset of Palo Alto Networks customers that have deployed it, of which only a fraction…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

An OS command injection vulnerability in Palo Alto Networks Expedition allows an unauthenticated attacker to run arbitrary OS commands as root in Expedition, resulting in disclosure of usernames, cleartext passwords, device configurations, and device API keys of PAN-OS firewalls.

CISA Known Exploited Vulnerability
Affected
Palo Alto Networks Expedition
Required action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
paloaltonetworks
Products
expedition
Weakness
CWE-78
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:C/RE:H/U:Amber

In the news