ZeroHour

CVE-2024-9465

KEV PoC niche1

Unauthenticated SQL Injection in Palo Alto Networks Expedition

CISA: Palo Alto Networks Expedition SQL Injection Vulnerability

CVSS 4.0
9.2 critical
EPSS
100%p100
Published
()
KEV added
AI analysis

Palo Alto Networks Expedition contains an unauthenticated SQL injection flaw (CWE-89, CVSS 4.0 score 9.2) that an attacker can trigger over the network by sending crafted requests to the Expedition web application without any credentials. Successful exploitation reveals the contents of the Expedition database, including password hashes, usernames, device configurations, and device API keys, and additionally allows the attacker to create and read arbitrary files on the Expedition system. Anyone running Expedition — a migration and configuration-conversion tool typically deployed on-premises by organizations migrating to or managing Palo Alto Networks firewalls — is affected, while the firewalls themselves are not the direct target of this flaw. Palo Alto Networks has confirmed active exploitation, CISA added the vulnerability to its Known Exploited Vulnerabilities catalog on 2024-11-14, and EPSS assigns a 99.6% probability of exploitation within 30 days; public research also demonstrates it can be chained with other Expedition bugs for a full system compromise.

What to do: Upgrade Expedition to the patched release per Palo Alto Networks' security advisory, and restrict or remove internet exposure since the tool is not intended to be public-facing. Given confirmed in-the-wild exploitation, review Expedition logs for anomalous requests, rotate potentially harvested secrets such as device API keys, Expedition account credentials, and password hashes, and discontinue use of the product if mitigations cannot be applied. Also verify whether downstream firewall configurations were altered, since device configurations were accessible through the database.

Affected
Palo Alto Networks Expeditionall Expedition deployments prior to the vendor's patched release (no specific version range provided in the source data; CISA lists affected product simply as P
Estimated exposure
nichelikely low thousands of Expedition deployments worldwide (niche migration tool, only a fraction exposed to the internet) — Based on deployment patterns: Expedition is a purpose-built migration/conversion utility used only by a subset of Palo Alto Networks customers and partners rather than a mass-deployed product, implying an installed base in the low…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

An SQL injection vulnerability in Palo Alto Networks Expedition allows an unauthenticated attacker to reveal Expedition database contents, such as password hashes, usernames, device configurations, and device API keys. With this, attackers can also create and read arbitrary files on the Expedition system.

CISA Known Exploited Vulnerability
Affected
Palo Alto Networks Expedition
Required action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
paloaltonetworks
Products
expedition
Weakness
CWE-89
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:C/RE:H/U:Amber

In the news