
Cloud Vulnerability DB
A community-led vulnerabilities database
Palo Alto Networks’ Expedition tool contains multiple critical vulnerabilities (CVE-2024-9463, CVE-2024-9464, CVE-2024-9465, CVE-2024-9466, CVE-2024-9467), including OS command injection, SQL injection, cleartext storage of sensitive information, and cross-site scripting (XSS). These issues, with CVSS scores reaching 9.9, expose systems running Expedition to unauthorized access, credential theft, and administrative takeover. Exploitation requires minimal complexity and no user interaction, posing a critical risk to systems unless addressed promptly.
Expedition is a tool designed to help the migration process of configurations from supported vendors to Palo Alto Networks systems. Expedition allows users to convert configurations from vendors like Checkpoint, Cisco, or others to PAN-OS.
The identified vulnerabilities in Expedition include several OS command injection flaws (CVE-2024-9463 and CVE-2024-9464), enabling attackers—both authenticated and unauthenticated—to run arbitrary OS commands as root. This exposure allows access to sensitive data such as firewall credentials and API keys. Additionally, the SQL injection vulnerability (CVE-2024-9465) permits unauthenticated attackers to access Expedition’s database and retrieve critical information like password hashes and configuration details, with the potential to write arbitrary files to the system. Furthermore, CVE-2024-9466 reveals sensitive information in cleartext logs, and CVE-2024-9467 allows reflected XSS, which attackers can exploit to steal user sessions or perform phishing attacks. All vulnerabilities combined represent a substantial threat that requires urgent patching and securing of Expedition instances.
All versions of Expedition below 1.2.96 are affected.
It is recommended to upgrade to Expedition version 1.2.96 or later. This version addresses all identified vulnerabilities.
The following mitigation steps can be taken to minimize risk of exploitation:
Access Restrictions: Limit network access to Expedition systems to authorized personnel and networks only.
Rotate Credentials: Immediately after upgrading, rotate all Expedition-related usernames, passwords, and API keys, including those for firewalls and devices integrated through Expedition.
Monitor Logs and Check IoCs: Inspect access logs for HTTP requests targeting known vulnerable endpoints like /OS/startup/restore/restoreAdmin.php and /bin/CronJobs.php for signs of unauthorized activity. Additionally, run checks on the Expedition database for suspicious entries indicating potential compromises.
Shutdown Unused Instances: Disable Expedition software if it is not actively in use to minimize exposure.
Source: Wiz Research
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."