← back
CVE-2024-9465criticalunder attackCWE-89

Expedition: SQL Injection Leads to Firewall Admin Credential Disclosure

100Vexday Risk Score

Patch now. It under exploitation confirmed by CISA and has a working public exploit.

ssvc Actcvss 9.2epss 100%
from disclosure to weapon0 days
Published on NVDOct 9
1st PoCOct 9
CISA KEV+36d
exploitation probability
100%top 1% of all CVEs
observed exploitation
yesCISA + VulnCheck
7 public exploit(s)
Action required by CISAfederal deadline: 2024-12-05

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Summary

Falha de SQL injection não autenticada no Expedition, ferramenta da Palo Alto Networks usada para migrar configurações de outros vendors (Checkpoint, Cisco etc.) para PAN-OS. Um atacante sem credenciais consegue extrair todo o conteúdo do banco do Expedition — hashes de senha, usuários, configurações de dispositivo e API keys de firewalls PAN-OS integrados — e ainda criar/ler arquivos arbitrários no servidor. Importa porque o Expedition normalmente concentra credenciais de todos os firewalls que passaram pela migração, então comprometer essa caixa é um atalho para comprometer a infraestrutura PAN-OS inteira gerenciada por ela; a CISA confirma exploração ativa e o EPSS está praticamente no topo da escala (0.996).

Researched and written with AI from the vendor advisory and public analysis, with the sources above. Always confirm the fixed version in the official advisory before acting.
An SQL injection vulnerability in Palo Alto Networks Expedition allows an unauthenticated attacker to reveal Expedition database contents, such as password hashes, usernames, device configurations, and device API keys. With this, attackers can also create and read arbitrary files on the Expedition system.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:H/SI:N/SA:N/AU:N/R:U/V:C/RE:H/U:Amber
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.