CVE-2024-9465
Palo Alto Expedition vulnerability analysis and mitigation

Overview

An SQL injection vulnerability (CVE-2024-9465) affects Palo Alto Networks Expedition, a configuration migration tool. The vulnerability allows unauthenticated attackers to reveal Expedition database contents, including password hashes, usernames, device configurations, and device API keys. Additionally, attackers can create and read arbitrary files on the Expedition system. The vulnerability affects all versions of Expedition below 1.2.96 (Vendor Advisory, NVD).

Technical details

The vulnerability exists in the /bin/configurations/parsers/Checkpoint/CHECKPOINT.php endpoint, which is accessible without authentication and processes HTTP request parameters to construct SQL queries. The vulnerability allows attackers to inject malicious SQL commands through various parameters, enabling them to dump entire database tables using blind time-based SQL injection techniques. The vulnerability has received a CVSS v3.1 base score of 9.1 CRITICAL (Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N) (Horizon3 Research, NVD).

Impact

The vulnerability enables attackers to access sensitive information stored in the Expedition database, including password hashes, usernames, device configurations, and API keys. This access could potentially lead to compromise of connected PAN-OS firewalls and other integrated devices. The exposed data could be used for further attacks against the organization's network infrastructure (Wiz Blog, Vendor Advisory).

Mitigation and workarounds

Organizations should immediately upgrade to Expedition version 1.2.96 or later, which contains fixes for this vulnerability. Additional recommended mitigations include restricting network access to Expedition systems to authorized users and networks only, rotating all Expedition-related credentials after upgrading, and monitoring access logs for suspicious activity. If Expedition is not actively in use, it should be shut down to minimize exposure (Vendor Advisory).

Community reactions

The security community has responded with significant concern due to the critical nature of the vulnerability and its active exploitation. According to research data, approximately 23 Expedition servers were found exposed to the internet at the time of discovery, though this exposure is limited given the tool's intended use case (Horizon3 Research).

Additional resources


SourceThis report was generated using AI

Related Palo Alto Expedition vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2024-9463CRITICAL9.9
  • Palo Alto Expedition logoPalo Alto Expedition
  • cpe:2.3:a:paloaltonetworks:expedition_migration_tool
YesYesOct 09, 2024
CVE-2024-9464CRITICAL9.3
  • Palo Alto Expedition logoPalo Alto Expedition
  • cpe:2.3:a:paloaltonetworks:expedition_migration_tool
NoYesOct 09, 2024
CVE-2024-9465CRITICAL9.2
  • Palo Alto Expedition logoPalo Alto Expedition
  • cpe:2.3:a:paloaltonetworks:expedition_migration_tool
YesYesOct 09, 2024
CVE-2024-9466HIGH8.2
  • Palo Alto Expedition logoPalo Alto Expedition
  • cpe:2.3:a:paloaltonetworks:expedition_migration_tool
NoYesOct 09, 2024
CVE-2024-9467HIGH7
  • Palo Alto Expedition logoPalo Alto Expedition
  • cpe:2.3:a:paloaltonetworks:expedition_migration_tool
NoYesOct 09, 2024

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management