ZeroHour

CVE-2024-9464

moderate

Authenticated OS Command Injection in Palo Alto Networks Expedition

CVSS 4.0
9.3 critical
EPSS
83%p100
Published
()
Modified
AI analysis

CVE-2024-9464 is an OS command injection flaw (CWE-78) in Palo Alto Networks Expedition, the vendor's firewall migration and management tool, that lets an authenticated attacker inject and run arbitrary operating system commands with root privileges on the Expedition host. It is triggered over the network (AV:N) with only low privileges required, meaning any valid, authenticated Expedition session with crafted input, and it requires no user interaction or special conditions. Successful exploitation exposes the sensitive data Expedition stores during migrations, including usernames, cleartext passwords, device configurations, and API keys of managed PAN-OS firewalls. Any organization running Expedition is affected, typically those using the tool to migrate firewalls from other vendors to PAN-OS or to consolidate Panorama deployments. Palo Alto Networks and CISA have warned of active exploitation of Expedition vulnerabilities from this disclosure (CVE-2024-5910, CVE-2024-9463, CVE-2024-9465), related reporting indicates CISA has added the Expedition bugs to its Known Exploited Vulnerabilities catalog, and a very high EPSS score (82.6%, 100th percentile) indicates this flaw is highly likely to be exploited within 30 days.

What to do: Update Expedition to the latest software/content release available from Palo Alto Networks per its advisory (no fixed version is specified in the source data), and restrict the Expedition web interface to trusted management networks or VPN-only access. Because Expedition stores PAN-OS firewall credentials, configurations, and API keys — potentially in cleartext — rotate those credentials and API keys and review Expedition logs for unexpected authenticated activity.

Affected
Palo Alto Networks Expedition (firewall migration/management tool)
Estimated exposure
moderate≈ a few thousand exposed deployments (low thousands of internet-reachable Expedition instances within a modest overall install base) — Expedition is a niche migration/management appliance rather than a mass-market product, and public internet scans show only a low-thousands count of exposed Expedition web interfaces, while many deployments sit on internal management…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

An OS command injection vulnerability in Palo Alto Networks Expedition allows an authenticated attacker to run arbitrary OS commands as root in Expedition, resulting in disclosure of usernames, cleartext passwords, device configurations, and device API keys of PAN-OS firewalls.

Vendors
paloaltonetworks
Products
expedition
Weakness
CWE-78
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:C/RE:H/U:Amber

In the news