Palo Alto Networks fixed a critical bug in the Expedition tool
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2024-3596 | RADIUS Protocol under RFC 2865 is susceptible to forgery attacks by a local attacker who can modify any valid Response (Access-Accept, Access-Reject, or Access- RADIUS Protocol under RFC 2865 is susceptible to forgery attacks by a local attacker who can modify any valid Response (Access-Accept, Access-Reject, or Access-Challenge) to any other response using a chosen-prefix collision attack against MD5 Response Authenticator signature. NVD description · AI analysis pending | 9.0 | 15% |
| — | ||
| CVE-2024-5910 | Unauthenticated Admin Account Takeover in Palo Alto Networks Expedition CVE-2024-5910 is a missing authentication flaw (CWE-306) in Palo Alto Networks Expedition, a tool used to migrate, tune, and enrich firewall configurations. An attacker with network access to an Expedition instance can exploit the unauthenticated critical function to take over the Expedition admin account without any credentials. Once in control, the attacker can access configuration secrets, credentials, and other data imported into Expedition, and public research (horizon3.ai) shows it can be chained with other Expedition bugs for full system compromise. Any organization running Expedition — particularly instances reachable from the internet or shared networks — is affected. The flaw is actively exploited: it was added to CISA's Known Exploited Vulnerabilities catalog on 2024-11-07, carries a 91.8% EPSS exploitation probability, and is being exploited alongside related Expedition and firewall bugs (CVE-2024-9463, CVE-2024-9465). Do: Apply the vendor's patched Expedition release per Palo Alto Networks' advisory; if the tool is no longer needed, decommission or discontinue it, as CISA permits. Until patched, restrict network access to Expedition to trusted management hosts and remove it from internet exposure. Check Expedition logs for signs of unauthorized admin access and rotate any credentials or secrets stored in the tool. | 9.3 | 92% | KEV PoC |
| nichelikely low thousands of deployments worldwide; unknown for internet-exposed instances | |
| CVE-2024-5911 +1 in the same advisory: …5913 | An arbitrary file upload vulnerability in Palo Alto Networks Panorama software enables an authenticated read-write administrator with access to the web interfac An arbitrary file upload vulnerability in Palo Alto Networks Panorama software enables an authenticated read-write administrator with access to the web interface to disrupt system processes and crash the Panorama. Repeated attacks eventually cause the Panorama to enter maintenance mode, which requires manual intervention to bring the Panorama back online. NVD description · AI analysis pending | 7.0 group max | <1% |
| — | ||
| CVE-2024-5912 | An improper file signature check in Palo Alto Networks Cortex XDR agent may allow an attacker to bypass the Cortex XDR agent's executable blocking capabilities An improper file signature check in Palo Alto Networks Cortex XDR agent may allow an attacker to bypass the Cortex XDR agent's executable blocking capabilities and run untrusted executables on the device. This issue can be leveraged to execute untrusted software without being detected or blocked. NVD description · AI analysis pending | 6.8 | <1% | — | — |
Full article431 words · extracted from securityaffairs.com · click to collapse

Palo Alto Networks addressed five vulnerabilities impacting its products, including a critical authentication bypass issue.
Palo Alto Networks released security updates to address five security flaws impacting its products, the most severe issue, tracked as CVE-2024-5910 (CVSS score: 9.3), is a missing authentication for a critical function in Palo Alto Networks Expedition that can lead to an admin account takeover.
Palo Alto Networks Expedition is a tool designed to help users transition to and optimize Palo Alto Networks’ next-generation firewalls. It assists with the migration of configurations from other firewall vendors and legacy Palo Alto Networks devices to newer models. Additionally, Expedition provides automation and best practice adoption to improve security posture and operational efficiency.
“Missing authentication for a critical function in Palo Alto Networks Expedition can lead to an Expedition admin account takeover for attackers with network access to Expedition.” reads the advisory. “Expedition is a tool aiding in configuration migration, tuning, and enrichment. Configuration secrets, credentials, and other data imported into Expedition is at risk due to this issue.”
The vulnerability affects Expedition versions before 1.2.92. The researcher Brian Hysell reported the flaw to the security vendor.
The company is not aware of any attacks in the wild or public exploits targeting this issue.
The company recommends restricting network access to Expedition to authorized users, hosts, or networks.
Palo Alto also addressed a File Upload Vulnerability, tracked as CVE-2024-5911 (CVSS score: 7.0), in the Panorama Web Interface of PAN-OS.
“An arbitrary file upload vulnerability in Palo Alto Networks Panorama software enables an authenticated read-write administrator with access to the web interface to disrupt system processes and crash the Panorama.” reads the advisory. “Repeated attacks eventually cause the Panorama to enter maintenance mode, which requires manual intervention to bring the Panorama back online.”
The remaining issues addressed by the security vendor are:
| 6.8 | CVE-2024-5912 Cortex XDR Agent: Improper File Signature Verification Checks | Cortex XDR Agent 8.4Cortex XDR Agent 8.3-CECortex XDR Agent 8.3Cortex XDR Agent 8.2Cortex XDR Agent 7.9-CE | NoneNoneNone< 8.2.2< 7.9.102-CE | AllAllAll>= 8.2.2>= 7.9.102-CE | 2024-07-10 | 2024-07-10 |
| 5.4 | CVE-2024-5913 PAN-OS: Improper Input Validation Vulnerability in PAN-OS | Cloud NGFWPAN-OS 11.2PAN-OS 11.1PAN-OS 11.0PAN-OS 10.2PAN-OS 10.1Prisma Access | None< 11.2.1< 11.1.4< 11.0.5< 10.2.10< 10.1.14-h2None | All>= 11.2.1>= 11.1.4>= 11.0.5>= 10.2.10>= 10.1.14-h2All | 2024-07-10 | 2024-07-10 |
| 5.3 | CVE-2024-3596 PAN-OS: CHAP and PAP When Used with RADIUS Authentication Lead to Privilege Escalation | Cloud NGFWPAN-OS 11.2PAN-OS 11.1PAN-OS 11.0PAN-OS 10.2PAN-OS 10.1PAN-OS 9.1Prisma Access | NoneNone< 11.1.3< 11.0.4-h4< 10.2.10< 10.1.14< 9.1.19All | AllAll>= 11.1.3>= 11.0.4-h4>= 10.2.10>= 10.1.14>= 9.1.19None (Fix ETA: July 30) | 2024-07-10 | 2024-07-10 |
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, Palo Alto )
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/165641/security/palo-alto-networks-critical-bug-expedition.html