
Cloud Vulnerability DB
A community-led vulnerabilities database
An SQL injection vulnerability (CVE-2024-9465) affects Palo Alto Networks Expedition, a configuration migration tool. The vulnerability allows unauthenticated attackers to reveal Expedition database contents, including password hashes, usernames, device configurations, and device API keys. Additionally, attackers can create and read arbitrary files on the Expedition system. The vulnerability affects all versions of Expedition below 1.2.96 (Vendor Advisory, NVD).
The vulnerability exists in the /bin/configurations/parsers/Checkpoint/CHECKPOINT.php endpoint, which is accessible without authentication and processes HTTP request parameters to construct SQL queries. The vulnerability allows attackers to inject malicious SQL commands through various parameters, enabling them to dump entire database tables using blind time-based SQL injection techniques. The vulnerability has received a CVSS v3.1 base score of 9.1 CRITICAL (Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N) (Horizon3 Research, NVD).
The vulnerability enables attackers to access sensitive information stored in the Expedition database, including password hashes, usernames, device configurations, and API keys. This access could potentially lead to compromise of connected PAN-OS firewalls and other integrated devices. The exposed data could be used for further attacks against the organization's network infrastructure (Wiz Blog, Vendor Advisory).
Organizations should immediately upgrade to Expedition version 1.2.96 or later, which contains fixes for this vulnerability. Additional recommended mitigations include restricting network access to Expedition systems to authorized users and networks only, rotating all Expedition-related credentials after upgrading, and monitoring access logs for suspicious activity. If Expedition is not actively in use, it should be shut down to minimize exposure (Vendor Advisory).
The security community has responded with significant concern due to the critical nature of the vulnerability and its active exploitation. According to research data, approximately 23 Expedition servers were found exposed to the internet at the time of discovery, though this exposure is limited given the tool's intended use case (Horizon3 Research).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."